Security

Security overview

The technical and operational measures used to protect the tag experience, restrict access, operate services, and respond to concerns.

01

Encrypted connections

Traffic to Taggo services is protected in transit using modern HTTPS.

02

Private identifiers

Tag identifiers are designed to resist simple guessing and enumeration.

03

Abuse protections

Rate limits, validation, and service-level controls help deter automated misuse.

04

Controlled access

Access to production systems and personal data is restricted to legitimate operational needs.

05

Secure development

Changes are reviewed, dependencies are maintained, and security is considered throughout delivery.

06

Recovery planning

Backups and recovery procedures are designed to support service resilience.

Infrastructure

Modern foundations, chosen deliberately.

Taggo uses specialist providers for global delivery, data storage, notifications, and commerce. Each provider is considered part of the wider security and privacy boundary.

Edge and hosting
Cloudflare
Application services
Cloudflare Workers
Structured data
Cloudflare D1
Object storage
Cloudflare R2
Mobile experience
Flutter
Notifications
Apple Push Notification service and Firebase Cloud Messaging
Commerce
Shopify

Responsible disclosure

Found something that does not look right?

We welcome good-faith reports from security researchers and customers. Please give us a reasonable opportunity to investigate before sharing details publicly.

Email security@taggo.travel

Please include

  • A clear description of the issue
  • Steps that help us reproduce it safely
  • The affected page, tag flow, or service
  • Your preferred contact details

Please do not access other people’s data, disrupt the service, use social engineering, or publicly disclose an issue before we have addressed it.

Restrained roadmap

What we are strengthening next.

We publish only improvements we are prepared to work toward. Timelines may change as risks and customer needs evolve.

  1. In progressFormal incident-response playbooks and exercises
  2. PlannedExpanded account protection and session controls
  3. PlannedIndependent security testing as the service matures