Security

Last Updated September 27, 2026

A chip design is among the most valuable things a company owns. Tapeout is built so it never has to leave your hands. The agents run where your design already lives, use the tools and models you approve, and keep every action on your record.

  1. Runs inside your perimeter

    Tapeout deploys on infrastructure you control, on your own servers or in your private cloud, and runs fully air‑gapped. A deployment needs no outbound connection to Tapeout Labs, and no RTL, testbenches, logs, waveforms or results are ever sent to us.

  2. Your data stays yours

    Everything the agents read and produce stays in your environment, including Ledger, the record of every run, revision and verdict. You keep all rights in your designs and design data. We don’t train models on customer data, and our team has no access to a deployment unless you grant it for a specific task, for as long as you choose.

  3. Models you approve

    You decide which models the agents use. A deployment can run open‑weight models on your own hardware, so no prompt or design data reaches an outside model provider. If you connect a hosted model instead, that connection is yours to configure and govern.

  4. Your tools, your licenses

    The agents drive the simulators, formal tools and scripts you already license, through your license servers and job schedulers. They run under accounts you create, with the permissions you give them, and reach only the projects and machines you allow.

  5. Every action on the record

    Ledger records each action the agents take, including the command, its inputs, the tool and version, the output and the result it supports. The record stays on your systems, so your engineers and your auditors can trace any conclusion back to the run that produced it.

  6. Engineers keep signoff

    The agents investigate, rerun and report. Waivers and signoff stay with your engineers, and every decision records who made it.

  7. Export‑controlled work

    Because Tapeout runs entirely inside your environment, controlled technical data stays under the export‑control and data‑handling processes you already have.

  8. Security reviews

    We support your security and procurement review from the first conversation. Under NDA, we walk your team through our architecture, deployment model and controls, complete your security questionnaire, and agree confidentiality and data protection terms before any engagement begins.

  9. Incident response

    If a security incident ever affects information you’ve shared with us, we’ll notify you without undue delay, tell you what we know, and work with your team through investigation and remediation.

  10. Our websites

    Our websites never handle design data. Our Privacy Notice explains the limited information they collect.

  11. Reporting a vulnerability

    If you believe you’ve found a security issue in our websites or software, email security@tapeoutlabs.com with the details and the steps to reproduce it. We’ll acknowledge your report within three business days, keep you informed while we fix it, and credit you if you’d like.

    Please give us reasonable time to address an issue before disclosing it, and don’t access, change or keep data that isn’t yours while testing. We won’t pursue legal action against good‑faith research that follows these guidelines.