> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usetero.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Reviewer Map

> Fast lookup for common security questionnaire topics.

export const securityEmail = "security@usetero.com";

<Badge>Last reviewed: March 5, 2026</Badge>
<Badge>Owner: Security + Engineering</Badge>
<Badge>Review cadence: Quarterly</Badge>
<Badge color="blue">Status: Reference</Badge>

Use this page as the index for questionnaire completion. It maps common prompts to the right trust pages without requiring deep navigation.

## How to use this map

1. Find the closest questionnaire topic.
2. Start with the listed primary page.
3. Use the secondary page only if the reviewer asks for more depth.

## Architecture and boundaries

| Questionnaire topic                     | Primary page                                                               | Secondary page                                                             |
| --------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- |
| Architecture and trust boundaries       | [Security Architecture](/trust/architecture)                               | [Shared Responsibility](/trust/shared-responsibility)                      |
| Hosted vs self-hosted ownership         | [Shared Responsibility](/trust/shared-responsibility)                      | [Overview](/trust/overview)                                                |
| Tenant isolation and logical separation | [Security Architecture](/trust/architecture)                               | [Identity and Access](/trust/controls/identity-access)                     |
| Encryption in transit and at rest       | [Encryption Standard](/trust/policies/encryption-standard)                 | [Encryption and Key Management](/trust/controls/encryption-key-management) |
| Key management and key rotation         | [Encryption and Key Management](/trust/controls/encryption-key-management) | [Encryption Standard](/trust/policies/encryption-standard)                 |

## Identity and access

| Questionnaire topic                            | Primary page                                                                             | Secondary page                                         |
| ---------------------------------------------- | ---------------------------------------------------------------------------------------- | ------------------------------------------------------ |
| API identity and token controls                | [Identity and Access](/trust/controls/identity-access)                                   | [Shared Responsibility](/trust/shared-responsibility)  |
| Login and SSO protocol support                 | [Authentication and Password Standard](/trust/policies/authentication-password-standard) | [Identity and Access](/trust/controls/identity-access) |
| Automated user provisioning and deprovisioning | [Authentication and Password Standard](/trust/policies/authentication-password-standard) | [Identity and Access](/trust/controls/identity-access) |
| Inactive account disablement after inactivity  | [Authentication and Password Standard](/trust/policies/authentication-password-standard) | [Identity and Access](/trust/controls/identity-access) |
| Session timeout and reauthentication controls  | [Authentication and Password Standard](/trust/policies/authentication-password-standard) | [Identity and Access](/trust/controls/identity-access) |
| Device or IP-based session restrictions        | [Authentication and Password Standard](/trust/policies/authentication-password-standard) | [Network Security](/trust/controls/network-security)   |

## Data governance

| Questionnaire topic                                               | Primary page                                                                    | Secondary page                                                        |
| ----------------------------------------------------------------- | ------------------------------------------------------------------------------- | --------------------------------------------------------------------- |
| Data handling scope and stored data                               | [Data Handling](/trust/controls/data-handling)                                  | [Overview](/trust/overview)                                           |
| Subprocessors and third-party services                            | [Subprocessors and Third Parties](/trust/assurance/subprocessors-third-parties) | [Shared Responsibility](/trust/shared-responsibility)                 |
| Integration directionality and connectivity model                 | [Network Security](/trust/controls/network-security)                            | [Security Architecture](/trust/architecture)                          |
| Material change notice (security, availability, or data handling) | [Subprocessors and Third Parties](/trust/assurance/subprocessors-third-parties) | [Compliance and Assurance](/trust/assurance/compliance-and-assurance) |

## Cloud operations

| Questionnaire topic                             | Primary page                                                                         | Secondary page                                                                       |
| ----------------------------------------------- | ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ |
| Cloud services policy and baseline requirements | [Cloud Services Security Standard](/trust/policies/cloud-services-security-standard) | [Network Security](/trust/controls/network-security)                                 |
| Cloud security alert monitoring                 | [Incident Response](/trust/controls/incident-response)                               | [Cloud Services Security Standard](/trust/policies/cloud-services-security-standard) |

## AI and model governance

| Questionnaire topic                         | Primary page                                         | Secondary page              |
| ------------------------------------------- | ---------------------------------------------------- | --------------------------- |
| AI provider handling and deployment options | [AI Data Controls](/trust/controls/ai-data-controls) | [Overview](/trust/overview) |

## Assurance and legal

| Questionnaire topic                      | Primary page                                                          | Secondary page                                                    |
| ---------------------------------------- | --------------------------------------------------------------------- | ----------------------------------------------------------------- |
| Compliance status and current assurances | [Compliance and Assurance](/trust/assurance/compliance-and-assurance) | [Documents and Requests](/trust/assurance/documents-and-requests) |

## How we answer in-progress controls

When a control is incomplete, we answer with:

* current implementation status,
* compensating controls in place,
* target completion timing,
* and where evidence will be provided when complete.

## Need a full review packet?

Email [{securityEmail}](mailto:\{securityEmail}) with your checklist and timeline. We can provide additional evidence under NDA.
