Security & Trust

Last updated: 20 March 2026

Tenant isolation

Every customer record belongs to exactly one organization. Row-level security policies are enforced in the database on every table, keyed to active organization membership — not to application code — so a compromised client can never read another tenant's data.

Access control

Role-based access control covers organization admins, vendor risk managers, security and compliance analysts, procurement, business owners, executives and auditors. Privileged platform staff roles are separate from customer roles and every privileged action is written to an immutable audit log.

Authentication

Email/password and Google sign-in are supported. Users can enrol a TOTP authenticator app from Account security; when enrolled, a 6-digit code is required at every sign-in.

Encryption and storage

All traffic is served over TLS. Data is encrypted at rest. Uploaded evidence (SOC 2, ISO 27001, HITRUST, PCI, FedRAMP reports) is stored in a private bucket and served only through short-lived signed URLs to authorised members of the owning organization.

Payments

Card data never touches VendorQ infrastructure. Paddle acts as merchant of record and handles payment collection, storage of payment instruments, tax and invoicing.

Monitoring

Application and authentication events are logged. The platform correlates the CISA Known Exploited Vulnerabilities catalog and reputable security reporting against detected vendor technologies to surface exposure quickly.

Responsible disclosure

Report suspected vulnerabilities to security@terrasecure.co. Please include reproduction steps and avoid accessing data that is not yours. We acknowledge reports within two business days and do not pursue legal action against good-faith research.