Skip to main content
Last reviewed: March 5, 2026 Owner: Security + Engineering Review cadence: Quarterly Status: Implemented This page summarizes Tero’s encryption controls for cloud data and how key ownership and operations differ between hosted and self-hosted deployments.

Reviewer focus

  • How data is encrypted in transit and at rest
  • Who owns and administers encryption keys by deployment model
  • How Tero handles key visibility, rotation, and revocation

Implementation status (March 5, 2026)

Tero encrypts sensitive and confidential data paths in transit and at rest in hosted environments.

Encryption controls

Key ownership and access model

Rotation and revocation baseline

  • Key lifecycle follows cloud-provider rotation and lifecycle controls.
  • Tero supports rotation and revocation for integration credentials and secrets.
  • Tero supports emergency revocation for compromised credentials.

Evidence you can request

Exceptions and governance

Any exception requires documented approval, compensating controls, and a time-bound remediation plan. Evidence requests: