Skip to main content
Last reviewed: March 5, 2026 Owner: Security + Engineering Review cadence: Quarterly Status: Implemented Tero requires TLS for integration traffic and protects hosted endpoints at the Cloudflare edge. This page covers that baseline and the connectivity options by deployment model.

Reviewer focus

  • How traffic reaches Tero and where TLS is terminated
  • Which WAF and DDoS controls protect hosted endpoints
  • What network restriction options are supported for stricter deployment requirements

Implementation status (March 5, 2026)

Tero exposes hosted APIs through controlled public endpoints behind Cloudflare edge protections. Self-hosted deployments are customer-controlled for perimeter and routing policy.

Network path diagram

Connectivity baseline

Edge protection model (hosted)

Traffic and termination model

Evidence you can request

Exceptions and governance

Any network-control exception requires documented risk, compensating controls, and a target remediation date. Evidence requests: