Trust Centre
Everything a vendor assessment asks for, in one place. Every figure on this page is the one the legal documents use, because both read from the same source.
Where a control is not in place, this page says so. A pack that only lists strengths is not worth reading.
Company
- Legal entity
- Teralo Pty Ltd
- ABN
- 98 634 996 115
- ACN
- 634 996 115
- Jurisdiction
- Sydney, NSW, Australia
- Governing law
- New South Wales, Australia
- Founder
- Ross Sanderson
The registered office is supplied on request, on signed Order Forms and in vendor onboarding packs. It is a residential address and is not published. Contact support@teralo.co for it, or for anything else on this page.
Certifications
Teralo holds no SOC 2, ISO 27001 or IRAP certification. ISO 27001 is the target, and no date is promised for it. What stands in their place is on this page and on the Security page: the controls that are in place, the testing performed, and the evidence Teralo can produce on request.
Where data rests
Two locations, two different guarantees. Teralo states them separately rather than as one claim about Australia, because only one of them is a commitment.
Supabase Postgres
CommittedSydney, Australia (AWS ap-southeast-2)
Project records, accounts, inductions and biometric templates
The region is fixed when the Supabase project is created and cannot change without a migration.
Cloudflare R2
Best effortOceania
Uploaded files: documents, drawings, photos, mail and meeting attachments, signed PDFs
The bucket carries Cloudflare's Oceania location hint. Cloudflare treats a hint as placement optimisation rather than a guarantee, and publishes no Australian jurisdiction that would make it one.
Security posture
- Multi-factor authentication
- Time-based one-time passcodes (TOTP) with single-use backup codes. Available to every user and mandatory for Teralo staff accounts with administrative access. Organisation-wide enforcement is not available yet.
- Backups and recovery
- Automated daily backups of the application database, retained for seven days. Recovery point objective up to 24 hours. Recovery time objective: not published. No documented restore drill has been performed, so no tested recovery time is claimed.
- Penetration testing
- Automated penetration testing using the open-source Shannon agent (Keygraph). Periodic, covering authentication, authorisation, injection, cross-site scripting and server-side request forgery. Most recent completed run 30 July 2026. The report can be provided under a non-disclosure agreement.
- Availability
- Teralo targets 99.99% and commits to 99.9% monthly, with service credits behind the commitment. See the Service Level Agreement.
Insurance
- Professional Indemnity A$5,000,000
- Public and Products Liability A$10,000,000
- Cyber Liability A$100,000
Certificates of currency are provided on written request. The limits are stated in clause 20 of the Master Terms, so they are contractual rather than marketing copy.
Sub-processors
10 providers in total, 7 of which touch data an organisation puts into a project. Each is named with its purpose, the data it receives and where it processes that data. The list last changed on 2 September 2026.
Teralo notifies customers before a new provider starts processing, and a customer on a written agreement may object on reasonable data protection grounds.
Documents
- Security
- Master Terms
- Schedule A: Click-Through
- Schedule B: Enterprise
- Schedule C: Project Licence
- Data Processing Agreement
- Service Level Agreement
- AI Product Terms
- Acceptable Use Policy
- Privacy Policy
- Sub-processors
- Landing Page Cookie Policy
- Application Cookie Policy
- Modern Slavery Statement
- Trademark Guidelines