Trust Center

Everything a vendor assessment asks for, in one place. Every figure on this page is the one the legal documents use, because both read from the same source.

Where a control is not in place, this page says so. A pack that only lists strengths is not worth reading.

Company

Legal entity
Teralo Pty Ltd
ABN
98 634 996 115
ACN
634 996 115
Jurisdiction
Sydney, NSW, Australia
Governing law
New South Wales, Australia
Founder
Ross Sanderson

The registered office is supplied on request, on signed Order Forms and in vendor onboarding packs. It is a residential address and is not published. Contact support@teralo.co for it, or for anything else on this page.

Certifications

Teralo holds no SOC 2, ISO 27001 or IRAP certification. ISO 27001 is the target, and no date is promised for it. What stands in their place is on this page and on the Security page: the controls that are in place, the testing performed, and the evidence Teralo can produce on request.

Where data rests

Two locations, two different guarantees. Teralo states them separately rather than as one claim about Australia, because only one of them is a commitment.

Supabase Postgres

Committed

Sydney, Australia (AWS ap-southeast-2)

Project records, accounts, inductions and biometric templates

The region is fixed when the Supabase project is created and cannot change without a migration.

Cloudflare R2

Best effort

Oceania

Uploaded files: documents, drawings, photos, mail and meeting attachments, signed PDFs

The bucket carries Cloudflare's Oceania location hint. Cloudflare treats a hint as placement optimisation rather than a guarantee, and publishes no Australian jurisdiction that would make it one.

Security posture

Multi-factor authentication
Time-based one-time passcodes (TOTP) with single-use backup codes. Available to every user and mandatory for Teralo staff accounts with administrative access. Organisation-wide enforcement is not available yet.
Backups and recovery
Automated daily backups of the application database, retained for seven days. Recovery point objective up to 24 hours. Recovery time objective: not published. No documented restore drill has been performed, so no tested recovery time is claimed.
Penetration testing
Automated penetration testing using the open-source Shannon agent (Keygraph). Periodic, covering authentication, authorisation, injection, cross-site scripting and server-side request forgery. Most recent completed run 30 July 2026. The report can be provided under a non-disclosure agreement.
Availability
Teralo targets 99.99% and commits to 99.9% monthly, with service credits behind the commitment. See the Service Level Agreement.

Insurance

  • Professional Indemnity A$5,000,000
  • Public and Products Liability A$10,000,000
  • Cyber Liability Not held

Certificates of currency are provided on written request. The limits are stated in clause 20 of the Master Terms, so they are contractual rather than marketing copy.

Sub-processors

10 providers in total, 7 of which touch data an organisation puts into a project. Each is named with its purpose, the data it receives and where it processes that data. The list last changed on 2 September 2026.

Teralo notifies customers before a new provider starts processing, and a customer on a written agreement may object on reasonable data protection grounds.

See the full list

Documents