Terret

Terret Security

Terret Security is an enterprise-grade, SOC 2 Type 2 compliant Revenue Operations & Intelligence platform hosted on AWS that prioritizes robust data protection through AES-256 encryption, continuous monitoring, annual penetration testing, and proactive patch management to ensure the confidentiality, integrity, and security of sensitive customer data.

Enterprise-grade security you can trust

Not only do we build world-class features, but we are also SOC 2, Type‑2 compliant. We built our platform with a laser focus on enterprise-grade reliability, security, and data protection for our customers.

  • SOC 2 Type 2
  • AWS Hosted
  • CSA Star Level 1
  • AES-256 Encryption

Security is at our core

At Terret, security is core to our business and product. It is a fundamental part of our platform and is essential to our business. As a Revenue Operations & Intelligence platform, we analyze and process sensitive data — revenue, call, and activity — for our customers.

Our customers and partners trust us with their sensitive data, and we shoulder the responsibility to ensure appropriately managed security, confidentiality, and integrity of that data. We pride ourselves on our commitment to having the most robust security practices and safeguards implemented across the entire application stack and being proactive and responsive to our customers’ data security.

Exceeds compliance standards

End-to-end security protection

Terret is hosted entirely on Amazon Web Services (AWS), providing end-to-end security and privacy features built-in. Our team takes additional proactive measures to ensure a secure infrastructure environment.

Annual SOC 2 and Pen Tests

We have been SOC 2 Type 2 compliant since 2020. We do a comprehensive annual retest of all our security and privacy controls, plus an annual application and infrastructure penetration test. Reports available upon request.

  • SOC 2 Type 2 since 2020
  • CSA Star Level 1

Patch management

Ongoing internal network security audits and scanning give us an overview for quickly identifying impacted systems. Operating systems, software, frameworks, and libraries are regularly updated. High or critical vulnerabilities trigger prompt hotfixes and patches.

  • Continuous monitoring

We put you in control

With Terret, we are committed to providing the highest security measures to ensure your data remains safe while giving you the control you need.

Granular security policies

Selectively allow or deny field access for your organization. Easily set custom expiration dates for any data fields to further protect your data.

Auditable log access

Quickly audit our security log at any time and in real-time. This level of detail puts you in full control of your own data.

User consent supported

Manage consent and access to applications at the user level. Alternatively, centralize the decision-making process with your security administrator team.

Top security and privacy features

Protected by Amazon Web Services

All infrastructure is hosted on AWS. Our team takes additional proactive measures beyond AWS defaults to keep data isolated and resilient.

SSO and dual-factor authentication

Login is supported only via Single Sign-On (SSO) for Google Apps and Office 365. Terret never stores user passwords in our database.

Principle of least privilege access

Users can only access functions, data files, and resources for which they have specific authorization. Security groups restrict access to minimum required levels across all servers.

Data encryption at rest and in motion

AES-256 encryption validated against FIPS 140-2. TLS is used for all connections. All sensitive data is encrypted at rest and in transit across all networks.

Threat protection & monitoring

Malicious data control

All SQL queries, HQL, OSQL, NOSQL and stored procedures are protected against SQL injection. Terret has security controls to prevent LDAP injection, OS command injection, Remote File Inclusion, XML attacks, and DOM Cross-Site Scripting (XSS) attacks.

Vulnerability management

Terret proactively monitors our infrastructure to identify any vulnerabilities and continuously works with security researchers to verify and address any issues. Refer to our Vulnerability Disclosure Policy for more details.