Trust & Safety

Security at Tula

Tula brings conversations, communities and payments together in one place. That convenience also creates an important responsibility: compromising a conversation should not automatically mean compromising someone's money.

That principle guides how we are building security across Tula.

A Tula login, a trusted device and permission to move money are not the same thing.

We designed them that way deliberately.

Private conversations by design

Personal conversations on Tula are end-to-end encrypted.

One-to-one conversations use Signal Protocol-based encryption, while group conversations use Messaging Layer Security (MLS). End-to-end encryption is designed so that message content can be read by the participants in the conversation, rather than by Tula while messages travel through our systems.

Encryption, however, is only one part of account security. A secure messaging system must also protect users when phones are lost, credentials are stolen or someone attempts to register another device.

A phone number is not the same as identity

A phone number is useful for finding and verifying an account, but possession of a phone number or verification code alone should not automatically grant complete authority over an account.

Tula separates several security concepts:

  • account authentication;
  • trusted devices;
  • encrypted messaging identities;
  • account recovery; and
  • authority to move money.

This means successfully signing in does not necessarily give a newly introduced device immediate financial authority.

Devices build trust over time

Tula associates accounts with individual devices rather than treating every successful login as equivalent.

When an established account suddenly appears on another device, Tula can distinguish that new device from devices the user has previously trusted.

A legitimate phone upgrade, a lost-phone recovery and an unexpected second device are therefore different security situations.

Where an existing trusted device is still active, an unexpected device attempting to access the same account may be subjected to additional verification and temporary restrictions.

Protecting money separately from chat

Tula treats communication authority and financial authority separately.

Being able to access an account or send a message should not automatically mean that a device can move money.

Sensitive financial actions are subject to additional controls, including device trust, transaction authorization and security-risk checks.

Tula is being designed so that a device under recovery, quarantine or elevated security review can have financial functionality restricted even when some non-financial parts of the application remain available.

In-chat payments stay bound to the person you are talking to

When a user initiates an integrated Tula payment from a one-to-one conversation, the payment beneficiary is resolved from the registered Tula participant in that conversation.

The recipient is not silently replaced by a phone number supplied by the other participant.

For supported group contribution flows, payments are similarly associated with the registered contribution account configured for that group.

Users should still remain cautious if somebody asks them in a message to ignore Tula's payment flow and instead send money through an unrelated external number or account.

New devices may be visible to people you talk to

Account takeover is not only a threat to the account owner's money. Attackers may also try to exploit the trust that friends, relatives and colleagues already have in the person whose account has been compromised.

Tula is therefore developing device-security signals that can help users understand when a contact has recently started messaging from a new or security-restricted device.

Where appropriate, Tula may display additional warnings around unusual financial requests while an account or device is undergoing security verification.

These warnings are intended to provide context — not to publicly accuse an account holder of wrongdoing.

When credentials appear compromised

Security credentials do not exist in isolation.

For example, a correct Security PIN and phone verification code presented by an expected trusted device may be legitimate. The same credentials unexpectedly presented by a new device while the established device remains active can indicate that those credentials have been exposed.

Tula is designing protections for serious security conflicts that can temporarily restrict outgoing financial activity while the account owner's identity is re-established.

During such protection, receiving funds may be treated separately from moving funds out of the account.

Account recovery

Account recovery must not become an easier way around the protections applied during normal use.

Tula's recovery architecture is designed to combine independent signals rather than relying entirely on one password, PIN, phone number or SMS message.

Depending on the security circumstances, recovery may involve trusted-device verification, additional security controls and identity re-verification.

For customers whose financial identity has already been verified, higher-risk recovery can involve re-verifying that the person recovering the account is the same person associated with the established verified identity.

Protecting users from suspicious links and impersonation

Encryption protects the confidentiality of a conversation, but it cannot make every link or message trustworthy.

Never share your Tula Security PIN, verification codes or sensitive payment credentials with another person. Tula will never contact you in a chat and ask you to send us your Security PIN or one-time verification code.

Be particularly cautious when someone asks you to:

  • install an application from an unfamiliar link;
  • enable unusual device permissions;
  • share a verification code;
  • urgently send money;
  • ignore an account-security warning; or
  • send money to a different number because their normal Tula payment method is supposedly unavailable.

What Tula will never ask you for

Tula support will never ask you to disclose your full Security PIN or a one-time authentication code inside a chat.

Do not send these credentials to anyone, even if they claim to work for Tula.

Security is a continuing process

There is no single feature that eliminates account takeover, malware, phishing or financial fraud.

Our approach is therefore based on limiting the damage that any one compromised credential, device or session can cause.

We continue to develop Tula's protections across encryption, device security, identity verification, payments, fraud detection and account recovery.

Reporting a vulnerability

If you believe you have discovered a security vulnerability in Tula, please report it to [email protected]. We appreciate reports made in good faith and will work with you on a responsible timeline for disclosure.

Keeping your account safe →Practical steps, warning signs, and what to do if something looks wrong.Why a verification code isn't enough →The thinking behind separating identity, devices and money.