Security

Enterprise-grade security for AEC project data

Project contracts, BOQs, financial data, and site documents are mission-critical assets. TerraVo is built to protect them with the same rigour as a financial platform.

SOC 2 Aligned
AES-256 Encrypted
GDPR Ready
99.9% Uptime SLA
ISO 27001 Controls

Compliance & certifications

Designed to meet the standards your clients and regulators require.

Compliance

SOC 2 Type II Aligned

Our controls and processes are aligned with SOC 2 Type II requirements across Security, Availability, and Confidentiality trust service criteria.

Privacy

GDPR & PDPA Ready

Data processing agreements, right-to-erasure workflows, and consent management support GDPR and regional data protection requirements.

Standards

ISO 27001 Controls

Information security policies, risk management, and vendor assessment procedures aligned with ISO 27001 information security management.

Security architecture

Every layer of the stack is hardened.

AES-256 Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Encryption keys are managed separately from data using envelope encryption.

Role-Based Access Control

Granular permission sets let administrators define exactly what each user can view, create, edit, or export — at the project, module, and field level.

Full Audit Logs

Every action — from document edits to permission changes — is logged with user identity, timestamp, and IP address. Logs are immutable and exportable.

Data Residency Options

Choose where your data lives. TerraVo supports UAE, KSA, India, and EU data residency options to meet local regulatory requirements.

Automated Backups

Point-in-time recovery with daily encrypted backups retained for 30 days. Cross-region replication ensures your data survives any single-region outage.

99.9% Uptime SLA

Redundant infrastructure across multiple availability zones with automatic failover. Planned maintenance is scheduled outside business hours with advance notice.

Identity & access

Control who can see and do what — at every level of your organisation.

Single Sign-On (SSO) via SAML 2.0 and OIDC
Multi-factor authentication (MFA) enforced by policy
Session timeout and concurrent session controls
IP allowlisting and geofencing
API key scoping and rate limiting
Inactive account auto-deprovisioning

Data practices

Specific technical parameters, not vague assurances.

Encryption at restAES-256
Encryption in transitTLS 1.3
Password hashingbcrypt (cost 12)
Backup frequencyDaily + continuous WAL
Backup retention30 days
Recovery time objective< 4 hours
Recovery point objective< 1 hour
Penetration testingAnnual (third-party)

Responsible disclosure

Found a vulnerability? We operate a responsible disclosure programme. Report security issues to security@terravo.cc. We acknowledge reports within 24 hours and aim to resolve critical issues within 72 hours.

Security questions? Talk to our team.

We share detailed security documentation, penetration test summaries, and data processing agreements with enterprise customers.

Request a Security Review