Security & Trust
Last updated: 20 March 2026
Tenant isolation
Every customer record belongs to exactly one organization. Row-level security policies are enforced in the database on every table, keyed to active organization membership — not to application code — so a compromised client can never read another tenant's data.
Access control
Role-based access control covers organization admins, vendor risk managers, security and compliance analysts, procurement, business owners, executives and auditors. Privileged platform staff roles are separate from customer roles and every privileged action is written to an immutable audit log.
Authentication
Email/password and Google sign-in are supported. Users can enrol a TOTP authenticator app from Account security; when enrolled, a 6-digit code is required at every sign-in.
Encryption and storage
All traffic is served over TLS. Data is encrypted at rest. Uploaded evidence (SOC 2, ISO 27001, HITRUST, PCI, FedRAMP reports) is stored in a private bucket and served only through short-lived signed URLs to authorised members of the owning organization.
Payments
Card data never touches VendorQ infrastructure. Paddle acts as merchant of record and handles payment collection, storage of payment instruments, tax and invoicing.
Monitoring
Application and authentication events are logged. The platform correlates the CISA Known Exploited Vulnerabilities catalog and reputable security reporting against detected vendor technologies to surface exposure quickly.
Responsible disclosure
Report suspected vulnerabilities to security@terrasecure.co. Please include reproduction steps and avoid accessing data that is not yours. We acknowledge reports within two business days and do not pursue legal action against good-faith research.