Skip to main content
Last reviewed: March 5, 2026 Owner: Security + Engineering Review cadence: Quarterly Status: Implemented This standard defines how Tero approves, configures, and operates cloud services to a consistent security baseline.

What this standard answers

  • How Tero approves new cloud services before production use
  • What minimum security requirements apply to cloud configuration and operations
  • How Tero handles cloud security alerts and material service changes

Implementation status (March 5, 2026)

Tero uses a defined cloud-service approval and operations baseline for hosted delivery.

Approval requirements before production use

Minimum cloud security baseline

Monitoring and response baseline

Material change communication

  • Tero communicates material security, availability, or data-handling changes in advance where required by contract or plan terms.
  • Tero communicates incident-driven or emergency changes as soon as it understands the impact, including remediation context.

Hosted vs self-hosted boundary

Evidence map

Exceptions and governance

Any baseline exception requires documented risk acceptance, compensating controls, owner approval, and a time-bound remediation plan. Questions: