We run the same review on ourselves.

Since 2020, we've helped enterprises navigate global privacy frameworks and heavy regulations to decide what is safe to build—from new products and AI use cases to vendor integrations. Our customers trust us with those decisions. This page is how we earn it.

Certifications and audits

Independently assessed, and reassessed every year.
SOC 2 ® Type II
Audited annually against the Security Trust Services Criteria. Our SOC 2 examination is conducted by Zero Day CPA.
Continuous since 2022 / Audited annually
Penetration Testing
Annual third-party penetration testing by Coalfire, with findings remediated under our defect prioritization SLA.
Conducted annually
Continuous Monitoring
Controls monitored continuously through Secureframe, not sampled at audit time.
Always on

Request our SOC 2 report

Our current SOC 2 Type II report is available to customers and active evaluations under NDA. Tell us who you are and what you need, and we’ll take it from there.
Product security
How the TerraTrue platform protects the data you put into it.
Your data stays in your VPC
The Data Catalog uses an agent-based architecture to scan cloud environments and databases. Confidential customer data and credentials never leave your infrastructure.
Identity that stays in sync
SAML single sign-on and SCIM provisioning with Okta, Entra ID, JumpCloud, and OneLogin. Group sync carries permissions, review team membership, and access groups across from your IdP and deprovisioning is automatic.
Granular, layered permissions
Nineteen distinct roles, each granted or withheld on its own, at the level of an individual, a review team, or the whole organization. Team membership is dynamic, so permissions follow the team as people join and leave it.
Scoped access for AI agents
Connecting an assistant through our MCP server uses a dedicated API user that an administrator creates and assigns granular permissions to — not a blanket key.
Icon of a lock
Encryption and hosting
TLS 1.2+ in transit, AES-256 or better at rest. TerraTrue is hosted entirely on Google Cloud Platform.
Audit trail
Every review action, approval, and configuration change is recorded and exportable for your own audit.
Do you train models on our data?

No — We do not use customer inputs, uploaded documents, or generated suggestions to train, retrain, or fine-tune any model, our own or a third party's. Every AI call is a transactional API request to enterprise Google Cloud Vertex AI, whose service-specific terms prohibit using your prompts and outputs to train Google's models or improve its services for other customers. Prompts and responses are processed transiently, isolated to your request, and never shared across tenant boundaries. TerraTrue is hosted on Google Cloud and our AI calls go to Google Cloud Vertex AI, so your data does not leave Google Cloud for AI processing.

What can we turn off?

All of it, at three levels. An organization administrator can disable AI globally, which halts every external AI API call. Workflow managers opt in per workflow. The Risk Scorecard is off by default and requires both administrator activation and role-based permission.

What does the AI actually see?

Only what each feature needs.

FeatureData processed
Attachment InsightsDocument content
Workflow AI SuggestionsDocument content and your workflow questions
Document SummaryDocument content
Risk ScorecardDocument content, your historical launch data, your taxonomy configuration
What if we connect our own AI assistant?

Our MCP server is accessed through a dedicated API user that your administrator creates and scopes with granular permissions. The agent can reach only what that user is permitted to reach, and we recommend scoping it to the minimum the use case needs. Those requests originate in your own AI platform under your agreement with that provider — TerraTrue does not transmit your data to Anthropic, OpenAI, or Microsoft on your behalf, and they are not TerraTrue subprocessors.

Does the AI decide anything?

No — Every output is advisory. Suggestions arrive with citations to the source text they came from, and a person reviews and accepts them before anything is recorded.

What if my question isn't listed here?

Contact Security at security@terratrue.com for any questions or feedback.

Privacy and data protection

The documents your legal and procurement teams will ask for.
Data processing agreement
A DPA forms part of your contract with us and is negotiated as part of the agreement.
Report a Vulnerability
We welcome responsible disclosure. If you have discovered a potential security vulnerability, please report it to security@terratrue.com. Our security team reviews every report.