> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usetero.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Incident Response and Resilience

> Detection, triage, communication, and recovery expectations for security incidents.

export const securityEmail = "security@usetero.com";

<Badge>Last reviewed: March 5, 2026</Badge>
<Badge>Owner: Security + Engineering</Badge>
<Badge>Review cadence: Quarterly</Badge>
<Badge color="green">Status: Implemented</Badge>

Tero detects, triages, communicates, and follows through on incidents. This page describes what you can expect at each phase.

## Reviewer focus

* How Tero responds to security-relevant incidents
* What customers can expect for communication during material incidents
* How resilience controls support recovery and continuity

## Implementation status (March 5, 2026)

Tero monitors security and operational events, including cloud security alerts, and triages them through incident-response workflows.

## Incident-response lifecycle

| Phase                        | Expected behavior                                         |
| ---------------------------- | --------------------------------------------------------- |
| Detection                    | Tero monitors and investigates security-relevant signals  |
| Triage                       | Tero assesses severity and impact                         |
| Containment and recovery     | Tero executes containment and service-restoration actions |
| Communication                | Tero notifies affected customers for material incidents   |
| Post-incident follow-through | Tero tracks corrective actions and improvements           |

## Customer communication baseline

* Tero notifies affected customers when it confirms a material incident.
* Communication includes impact scope, current status, and next steps.
* Tero keeps sending updates until it resolves the customer-impacting risk.

## Resilience controls

| Area                    | Approach                                                                                        |
| ----------------------- | ----------------------------------------------------------------------------------------------- |
| Cloud security alerting | Tero monitors provider and platform security alerts and triages them through incident workflows |
| Backups                 | Encrypted backups with retention controls                                                       |
| Recovery                | Operational recovery procedures and runbooks                                                    |
| Deployment resilience   | Managed cloud service patterns and operational controls                                         |

## Hosted vs self-hosted boundary

| Area                              | Tero-hosted | Self-hosted |
| --------------------------------- | ----------- | ----------- |
| Product incident support          | Tero        | Tero        |
| Infrastructure incident ownership | Tero        | Customer    |
| Runtime recovery execution        | Tero        | Customer    |

## Evidence you can request

| Topic                                  | Primary evidence                                                                                 |
| -------------------------------------- | ------------------------------------------------------------------------------------------------ |
| Architecture and monitoring controls   | [Security Architecture](/trust/architecture)                                                     |
| Data durability and retention behavior | [Data Handling](/trust/controls/data-handling), [Data Retention](/trust/policies/data-retention) |
| Assurance posture                      | [Compliance and Assurance](/trust/assurance/compliance-and-assurance)                            |

## Exceptions and governance

Any incident-handling exception requires explicit risk acceptance and time-bound remediation.

Evidence requests: [{securityEmail}](mailto:\{securityEmail})
