Skip to main content
Last reviewed: March 5, 2026 Owner: Security + Engineering Review cadence: Quarterly Status: Implemented This page covers how Tero configures AI provider integrations and which controls apply to AI-related data paths.

Reviewer focus

  • What data is sent to AI providers for classification and analysis workflows
  • Which provider and key-ownership modes are supported
  • How retention and training controls differ by provider and configuration

Implementation status (March 5, 2026)

Tero supports three AI deployment modes: hosted default provider path, bring-your-own provider credentials, and customer-controlled self-hosted provider routing.

AI workflow data scope

Tero sends AI providers only the data each classification or analysis task needs. By default, that means control-plane-relevant context and the telemetry samples the task requires. Tero does not ingest your full telemetry stream.

Provider and key ownership modes

Provider data controls (external policy alignment)

Deployment boundary

Model and provider coverage

  • Recommended frontier providers for production quality are Anthropic and OpenAI.
  • Bedrock and additional provider paths are supported as deployment-dependent integration options.
  • Additional open-source/local model paths (for example, Ollama-compatible) are possible, with quality validated case-by-case.

External references

Evidence you can request

Exceptions and governance

Any AI data-path exception requires documented approval, compensating controls, and a time-bound remediation plan. Evidence requests: