Enterprise security, built into the platform.
Tango is built on Copado's CRT platform and inherits its certified security program: SOC 2 Type 2 and ISO 27001. Scans run on temporary, read-only metadata access with no customer data extraction.
The certifications behind Tango.
Tango runs on Copado's CRT platform, so it inherits CRT's certified security controls. These are maintained and audited by Copado's security team; the reports themselves are available under NDA.
SOC 2 Type 2
Tango runs on Copado's CRT platform, which holds an active SOC 2 Type 2 attestation covering security, availability, and confidentiality controls. The full report is available to prospects and customers under NDA.
ISO/IEC 27001
The CRT platform Tango is built on is certified to ISO/IEC 27001 for its information security management system. The certificate is available on request under NDA.
Exactly what covers Tango, and what doesn't.
Tango's coverage comes from the Copado CRT platform it's built on. We're explicit about scope so security reviewers know precisely which certifications apply. FedRAMP Moderate covers a separate Copado GovCloud CI/CD subset and does not extend to Tango.
| Certification | Scope | Covers Tango? |
|---|---|---|
| SOC 2 Type 2 | Copado CRT Essentials + CI/CD | Yes — Tango runs on CRT |
| ISO/IEC 27001 | Copado CRT Essentials + CI/CD | Yes — Tango runs on CRT |
| FedRAMP Moderate | A specific Copado GovCloud CI/CD subset only | No — does not cover CRT or Tango |
How Tango accesses your environment.
Tango is designed to learn your environment's structure without touching the data inside it. Access is read-only, scoped, and temporary.
Read-only by default
A TangoIQ scan and ongoing analysis request temporary, read-only access to your environment. Tango reads. It does not write to, modify, or operate your production system.
Metadata, not your business data
Tango works from your environment's structure: custom tables, fields, business rules, and workflows. It is designed around platform metadata, not the records and customer data those workflows process.
Scoped, time-bound credentials
Access is granted with least-privilege, scoped credentials and is revoked after the assessment. There is no standing access and no performance impact on your environment.
Inherited platform controls
Because Tango is built on Copado's CRT platform, it inherits the encryption-in-transit, access-control, and audit-logging controls covered by CRT's SOC 2 Type 2 and ISO 27001 programs.
Security questions, answered.
The questions InfoSec teams ask us most often during evaluation.
Is Tango SOC 2 and ISO 27001 certified?
Yes. Tango runs on Copado's CRT platform, which maintains an active SOC 2 Type 2 attestation and ISO/IEC 27001 certification. Those controls cover the platform Tango is built on.
Can I get the actual SOC 2 report or ISO certificate?
Yes. The audit documents are available under a standard click-through NDA through our trust center, powered by Copado.
Is Tango FedRAMP authorized?
No. FedRAMP Moderate applies to a specific Copado GovCloud CI/CD subset only and does not cover the CRT platform or Tango. We call this out explicitly so there is no ambiguity during security review.
What does Tango access in our environment?
Temporary, read-only access to platform metadata: custom tables, fields, business rules, and workflows. Tango does not extract your customer data, and access is revoked after the assessment.
Where do the audit documents live?
Audit reports are single-sourced in our trust center, powered by Copado, so you always get the current, auditor-issued versions. This page is a public summary; the documents themselves are delivered under NDA.
Need our SOC 2 report or ISO 27001 certificate?
Tango's audit documents are delivered through our trust center, powered by Copado, under a standard click-through NDA.