Security Questionnaire
Last Updated: September 2026
This page answers the questions a vendor assessment normally asks, in the order they are normally asked. It exists so that onboarding Teralo does not wait two weeks for a spreadsheet to come back.
Answers are written to be accurate as configured rather than aspirational. Where a control is not in place, the answer says so. If a question here is answered "no", that is the real answer, and asking again will not change it.
For anything not covered, or for a copy of the current penetration testing report under a non-disclosure agreement, contact support@teralo.co.
Company
Legal entity name? Teralo Pty Ltd.
ABN and ACN? ABN 98 634 996 115, ACN 634 996 115.
Country of incorporation and principal place of business? Australia. Sydney, New South Wales.
Registered office address? Provided on request, on signed Order Forms and in vendor onboarding packs. It is a residential address and is not published.
Who are the directors? Ross Sanderson, founder.
How long has the company been operating? The company was registered in 2019. The Teralo platform is the current product.
How many staff? Teralo is a small team. Headcount is provided on request.
Do you use subcontractors or offshore development? Development is performed in Australia. Third parties that process data are listed at /legal/sub-processors.
Governing law for your contracts? New South Wales, Australia, with exclusive jurisdiction in the courts of Sydney.
Certifications and Audits
Teralo holds no SOC 2, ISO 27001 or IRAP certification. The individual answers follow.
Do you hold SOC 2? No.
Do you hold ISO 27001? No. It is the compliance target, and no date is committed.
Do you hold IRAP assessment? No.
Do you hold PCI DSS? Teralo does not store, process or transmit cardholder data. Payment details are captured by Stripe, which is PCI DSS Level 1 certified, and are never held by Teralo.
Can you provide a recent independent audit report? No independent audit has been performed. Teralo can provide the report from its most recent automated penetration test under a non-disclosure agreement.
Will you complete our security questionnaire? Yes, and this page answers most of it in advance.
Will you accept a security assessment or site visit? Yes, by arrangement. See the audit clause in the Data Processing Agreement.
Access Control and Authentication
How do users authenticate? With a work account through Google, Microsoft or Apple, or with an email address and password.
Do you support multi-factor authentication? Yes. Time-based one-time passcodes (TOTP) with single-use backup codes.
Is MFA mandatory? It is mandatory for Teralo staff accounts with administrative access. It is optional for customer users.
Can we enforce MFA across all of our users? No. Organisation-wide enforcement is not available yet.
Do you support SAML single sign-on? No.
Do you support SCIM provisioning and deprovisioning? No.
Do you support role-based access control? Yes. Users hold roles at organisation and project level, and access to a record follows from those roles.
Where is authorisation enforced? On the server. Hiding a control in the interface is not the access control mechanism.
How are passwords stored? Hashed. Teralo staff cannot retrieve a user password.
How is privileged access to production managed? Access is limited to staff who require it, and those accounts must have MFA enrolled.
Can a customer remove a user's access immediately? Yes, through the organisation's member management.
Do you support session timeout? Yes.
Do you log authentication events? Yes.
Encryption
Is data encrypted in transit? Yes, HTTPS with TLS 1.2 or above.
Is data encrypted at rest? Yes. The database is encrypted at rest with AES-256 by Supabase. Uploaded files are encrypted at rest with AES-256 in GCM mode by Cloudflare R2, including their metadata.
Who manages the encryption keys? The platform providers. Teralo does not operate its own key management service and does not offer customer-managed keys.
Do you support customer-managed or bring-your-own encryption keys? No.
Is data encrypted in backups? Backups are held by the database provider under the same at-rest encryption as the database.
Data Residency and Sovereignty
Where is our data stored? In two places, with two different guarantees.
The application database, which holds project records, account details, induction records and biometric templates, is in the AWS ap-southeast-2 region in Sydney. A Supabase project's region is fixed at creation, so this is a firm commitment.
Uploaded files, meaning documents, drawings, photos, mail and meeting attachments and signed PDFs, are in Cloudflare R2 in a bucket carrying Cloudflare's Oceania location hint. Cloudflare documents a location hint as a best effort rather than a guarantee, and publishes no Australian jurisdiction that would make it one. Teralo does not represent file storage as contractually resident in Australia.
Can you guarantee our data never leaves Australia? No, and Teralo will not claim otherwise. Static content is served from a global edge network, payment details go to Stripe, AI prompts go to Google and to PostHog in the United States, address lookups go to Mapbox and map tiles come from CARTO. All of them are listed at /legal/sub-processors.
Do you offer a sovereign or in-country-only deployment? No.
Will you notify us before moving where our data is stored? Yes. See clause 9 of the Master Terms.
Sub-processors
Do you publish a sub-processor list? Yes, at /legal/sub-processors, with each provider's purpose, the categories of data it receives and its processing location.
Is the list complete? Yes. It is generated from a single source of truth in the codebase rather than maintained by hand, and a test fails the build if a provider handling customer data is not described in the published documents.
Will you notify us before adding a sub-processor? Yes, before the new provider begins processing.
Can we object to a new sub-processor? Yes, within 30 days, on reasonable data protection grounds. Where no alternative is workable you may terminate the affected part of the service without penalty and receive a pro-rata refund.
Do sub-processors have equivalent obligations? Yes, and Teralo remains liable for their performance.
Data Protection and Privacy
Are you a controller or a processor? For customer project data, Teralo is the processor and the customer organisation is the controller. For account holders and website visitors, Teralo is the controller.
Do you have a Data Processing Agreement? Yes, at /legal/dpa. It applies without separate negotiation.
Do you comply with the Privacy Act 1988? Yes, and Teralo contracts on the basis that it is bound by it despite the small business exception.
Do you use our data to train AI models? No. Neither Teralo nor Google uses customer prompts or responses to train Large Language Models.
Are AI prompts logged? Yes. Every prompt and response is recorded in Teralo's product analytics, hosted by PostHog in the United States, for quality monitoring and debugging, and Teralo staff working on AI features can read them. This is stated plainly rather than buried.
Do you collect biometric information? Yes, where a project enables optional kiosk face sign-in and a worker consents. A numeric template is computed in the worker's browser and stored; the template cannot be reversed into a photograph, is never sent to an external biometric service, and is deleted when consent is withdrawn. The full description is in the Privacy Policy.
Do you sell personal information? No.
How do you handle data subject access requests? Requests relating to customer project data are directed to the customer organisation, which is the controller, and Teralo assists.
Backups and Disaster Recovery
Do you back up data? Yes. Automated daily backups of the application database, retained for seven days.
Is point-in-time recovery enabled? No, not currently.
What is your Recovery Point Objective? Up to 24 hours, which is what daily backups deliver.
What is your Recovery Time Objective? Teralo does not publish one, because no documented restore drill has been performed. It will be published once one has.
When did you last test a restore? No documented restore drill has been performed. Teralo states this rather than implying a test that did not happen.
Do you have a documented disaster recovery plan? Recovery depends on the managed platforms Teralo runs on. A formal, tested DR plan is not in place.
Do you have geographic redundancy? The database provider operates within its region. Teralo does not run a warm standby in a second region.
Availability and Support
What availability do you commit to? 99.9% monthly, with service credits. Teralo targets 99.99% and publishes actual availability on a live status page.
Are there service credits? Yes, from 10% to 50% of the monthly fee depending on the shortfall. The schedule is in the Service Level Agreement.
Can we terminate for chronic unavailability? Yes, after three consecutive months below the commitment, or any month below 99.0%, without penalty and with a pro-rata refund.
What are your support hours and response targets? Three tiers, set out in the Service Level Agreement. Order Form customers receive a one-business-hour target for a total outage and a dedicated phone line.
Do you provide a public status page? Yes, linked from the site footer.
How is scheduled maintenance notified? At least 48 hours in advance, capped at eight hours per calendar month, and scheduled outside business hours where practicable.
Incident Response
Do you have an incident response process? Yes: investigation, containment, remediation and post-incident analysis.
How quickly will you notify us of a breach? Without undue delay and in any event within 48 hours of becoming aware, with what is known at that point rather than waiting for a complete picture.
Will you help us meet our own notification obligations? Yes, including assessment against the Notifiable Data Breaches scheme.
Have you had a security breach? Teralo has not experienced a breach of customer data. Any future breach would be notified under the terms above.
Do you have cyber insurance? No. Teralo holds Professional Indemnity and Public and Products Liability cover, and states the absence of cyber cover rather than leaving the question unanswered.
Secure Development
Do you follow a secure development lifecycle? Changes are reviewed before release and tested in development and staging environments before deployment.
Do you perform penetration testing? Yes, automated penetration testing using the open-source Shannon agent, covering authentication, authorisation, injection, cross-site scripting and server-side request forgery. Testing is periodic rather than on a fixed schedule; the most recent completed run was in July 2026.
Do you use a third-party penetration testing firm? No, so there is no independent attestation letter.
Can we see a penetration test report? Yes, under a non-disclosure agreement.
Do you scan dependencies for vulnerabilities? Yes.
Do you have a vulnerability disclosure process? Report suspected vulnerabilities to support@teralo.co.
Are environments separated? Yes, development, staging and production are separate.
Is customer data used in non-production environments? No.
Personnel
Do you perform background checks? Background checks are performed where the role and jurisdiction warrant it.
Do staff sign confidentiality agreements? Yes.
Is security awareness training provided? Yes, proportionate to a team of this size.
How is access revoked when someone leaves? Accounts and credentials are revoked as part of offboarding.
Business Continuity
What happens to our data if Teralo ceases trading? Customer data remains exportable for 90 days after termination in CSV, XLS and PDF formats, and Teralo will assist with an extraction on request.
Do you offer source code escrow? No.
Can we export our data at any time? Yes, at any time during the term and for 90 days afterwards.
Can we buy a long-term archive? Yes. Teralo quotes for this on request, and records it as an option because construction records are reached for years after practical completion.
Are you dependent on any single supplier? Teralo runs on Cloudflare and Supabase. Both are named, with the data each holds, at /legal/sub-processors.
Commercial
What are your insurance limits? Professional Indemnity A$5,000,000. Public and Products Liability A$10,000,000. Cyber Liability is not held.
Will you provide certificates of currency? Yes, on written request.
What is your liability cap? Fees paid in the 12 months preceding the claim, with the usual carve-outs for death or personal injury and for fraud.
Do you offer an IP indemnity? Yes. Teralo indemnifies the customer against third-party claims that the platform infringes intellectual property rights, subject to the liability cap. This is given up front rather than negotiated.
Do you have a modern slavery statement? Yes, at /legal/modern-slavery. Teralo is below the reporting threshold and publishes one anyway.
Can we negotiate terms? Order Form customers can record Special Conditions. See Schedule B.
Contact
For anything this page does not answer, contact support@teralo.co.