Skip to main content
Reference information for security reviews and vendor assessments.

What each integration accesses

Each integration documents exactly what permissions it requires and why.
IntegrationWhat Tero accesses
DatadogLogs, metrics, traces, service catalog. Optional write access for exclusion filters.
SplunkLogs, index metadata. Optional write access for ingest actions.
GitHubRepository contents, PRs, issues. For code fixes and policy sync.
AnthropicTelemetry samples for AI classification. Zero retention.

Sub-processors

ServicePurposeDataLocation
Google Cloud PlatformInfrastructureControl plane, backupsUS
AnthropicAI classification (default)Samples, not persistedUS
WorkOSAuthenticationEmail, SSO tokensUS
StripePayments (self-service only)Billing infoUS
Self-hosted: No sub-processors. Everything runs in your infrastructure.
We notify customers 30 days before adding sub-processors that handle data.

Infrastructure

AreaImplementation
HostingGoogle Cloud Platform, us-central1, multi-zone
Encryption in transitTLS 1.3
Encryption at restAES-256 (database, backups, temp storage)
Key managementGCP KMS with automatic rotation
NetworkPrivate VPC, DDoS protection via Cloud Armor
Access controlSSO required, MFA enforced, role-based, time-limited production access
BackupsDaily, encrypted, 30-day retention, geo-redundant
MonitoringGCP Security Command Center, real-time alerts

Compliance

FrameworkStatus
SOC 2 Type 22026
Penetration testingQ1 2025
GDPRCompliant. DPA with SCCs available.
CCPACompliant. No data sales.
HIPAANot applicable (we don’t store PHI). Self-host if your logs contain PHI.

Controls

  • Role-based access, MFA required, least-privilege
  • Encryption everywhere (TLS 1.3, AES-256)
  • Code review required, automated testing, staged deployments
  • Incident response plan, 24-hour customer notification
  • Vendor risk assessment, documented data flows
  • Background checks, security training, access revocation on departure

Data retention

DataRetention
Account dataWhile active
Telemetry metadataWhile workspace active
Quality rulesWhile workspace active
Usage analytics2 years
Backups30 days
When you delete your account, data is removed within 30 days.

Your rights

You can request to access, correct, delete, or export your data. Email . We respond within 30 days. GDPR and CCPA rights fully supported.

Questions

Contact security team

Security review? Vendor assessment? Architecture questions? Email .