Skip to main content
Last reviewed: March 5, 2026 Owner: Security + Engineering Review cadence: Quarterly Status: Implemented This page defines who owns each control in each deployment model.

Reviewer focus

  • Which controls are Tero-owned vs customer-owned
  • How baseline integration traffic flows between customer systems and Tero
  • Where customers commonly add stricter controls

Implementation status (March 5, 2026)

Tero supports two deployment models:
  • Tero-hosted control plane
  • Self-hosted control plane in customer-managed infrastructure
Control ownership changes by model at the infrastructure and network layers.

Scope and integration boundary

  • Baseline integration model is customer-initiated outbound API traffic over HTTPS.
  • Baseline operation does not require vendor-initiated inbound connectivity into customer environments.
  • Identity policy inside the customer IdP remains customer-owned in both models.

Ownership model diagram

Responsibility matrix

Where customers tighten controls

  • Self-hosted deployment for full environment ownership
  • Customer IdP policy enforcement for authentication lifecycle controls
  • Destination allowlisting and private routing in customer networks
  • Customer-selected AI provider path where required
  1. Confirm identity and role mapping model.
  2. Confirm network allowlisting and routing requirements.
  3. Confirm data handling and retention expectations.
  4. Confirm incident communication paths and named contacts.

Evidence you can request

Exceptions and governance

If a control allocation does not match customer policy requirements, Tero and the customer document the gap, agree on compensating controls, and define a time-bound resolution plan before production use. Evidence requests: