Security and privacy
Exercise data is sensitive. We treat it that way.
What protects the data in Tactirun, and who is responsible for what. Every statement here describes how the product works today; ask us for the details behind any of them.
Where the data lives
- The hosted service runs on UpCloud in the EU (Finland).
- All traffic is encrypted in transit (HTTPS); pages load nothing from third parties — no analytics, fonts or CDNs, in the participant view either.
- If the data must stay inside your own network, install Tactirun on-premise.
Controller and processor
- For exercises and their participants, your organisation is the controller and we are your processor under a data processing agreement.
- For the accounts of your members we are the controller of the account data.
- The application's privacy notice lists what is processed, why, for how long, and our sub-processors.
Erasure, export and retention
- Erase a participant by e-mail address: their name, e-mail and attributes are removed, their devices signed out, their questions blanked and the run's stored report files deleted. Answers remain, anonymised, so the results still add up.
- Export everything held about a participant as a single file.
- Set a retention period: participants of archived runs are erased automatically after the number of months you choose (up to 120).
- Members export or delete their own account themselves.
- Generated report files are deleted after 30 days; share links expire after 24 hours.
Access and sign-in
- Every organisation is a separate tenant. An automated test calls every organisation endpoint as a member of another organisation and expects a refusal.
- Members work in roles, and participants never have an account: their access is a device session that ends when they leave, are removed or the run is archived.
- Passwords are stored with Argon2id; sign-in links are single-use and valid 15 minutes; sessions are short-lived and rotate, and reuse of a stolen session is detected.
- Join codes and PINs are protected against guessing: wrong PINs are limited per run and address.
Built for hostile networks
- A strict Content Security Policy (no inline or third-party scripts) and security headers on every response, checked by automated tests with the policy enforced.
- No cookies are used for tracking, and nothing is loaded from other sites.
- Rate limits per purpose — sign-in, joining, PIN attempts, answers, uploads, reports — keyed to the person where there is one, so a whole classroom behind one network address is not blocked.
- Uploaded files are checked by their content against an allow-list; spreadsheet exports neutralise formulas; rich text is stored as structured data, never as HTML.
Audit, backups and operations
- Every business action is recorded in an audit log, kept for 2 years, with no participant names in it.
- Backups are proven, not assumed: before a release, a scripted restore drill restores a backup into an empty installation and compares the row count of every table.
- Service-level objectives for availability, response times, live delivery and report generation, with alerts when they are at risk.
- Every change is scanned for leaked secrets and vulnerable dependencies; the container image is scanned before it is published.
Security questionnaire or DPA?
Write to info@tactirun.com — we answer security questionnaires and provide the data processing agreement.
Planning an exercise or a training course?
Tell us how many people take part and whether you want Tactirun hosted or on your own servers. We reply with a quote and, if you like, a walkthrough.