Security & Trust

Built for the teams that get audited.

Termitude protects your policies and consent records with modern encryption, strict tenant isolation, and an immutable audit-grade ledger.

Compliance

Where we stand today

We're transparent about what's done, what's in flight, and what's on the roadmap. SOC 2 Type II and ISO 27001 are both currently in progress.

GDPR
Ready

DPA available on request, EU data residency on Growth plan.

CCPA
Ready

Subject access, deletion, and portability workflows.

SOC 2 Type II
In progress

Audit in progress. Report expected Q4 2026.

ISO 27001
In progress

Stage 1 scheduled. Certification expected 2027.

In progress. We do not yet hold SOC 2 Type II or ISO 27001 certificates. If your procurement requires them today, contact us — we can share our audit roadmap, current controls evidence, and timelines.

Controls

Defense in depth

Encryption in transit

TLS 1.2+ on every public endpoint with HSTS preload and modern cipher suites only.

Encryption at rest

AES-256 disk encryption for the database, backups, and storage buckets.

Secrets management

API keys hashed with SHA-256 before storage; prefix-only display after creation.

Row-level isolation

Postgres RLS policies enforce strict tenant isolation on every read and write.

Immutable consent ledger

Append-only records keyed to content hashes — no edits, no deletes, no exceptions.

Hardened infrastructure

Edge runtime with no long-lived servers, least-privilege IAM, automated patching.

Audit logging

Every admin action, key usage and policy change recorded with actor, IP and timestamp.

Regional data residency

Pin tenants to EU or US regions on Growth — your data stays where you specify.

Operations

How we run the business

Security isn't only a feature checklist — it's how we hire, ship, and operate. These are the day-to-day practices behind the product.

  • Background checks

    All employees with production access pass background screening.

  • MFA enforced

    SSO + WebAuthn required for all staff; no shared credentials.

  • Least privilege

    Production access is JIT-granted, reviewed monthly, and fully logged.

  • Vendor review

    Sub-processors are reviewed annually; full list published below.

  • Penetration testing

    Annual third-party pentest with remediation SLAs.

  • Vulnerability disclosure

    security@termitude.com — we respond within 24h.

Sub-processors

Who we work with

Sub-processorLocationPurpose
Managed cloud infrastructureEU / USAApplication hosting, database, auth
CloudflareGlobalEdge network, DDoS protection
ResendUSATransactional email delivery
StripeUSABilling and payment processing
IntercomUSAPersonal data could be exchanged in help inquiries
MicrosoftEU / USA — as selectedPersonal data contained in communications sent through or uploaded to the services. Use of Azure OpenAI in which personal data may be shared in prompts written by end users.
Equus SoftwareEU, USA, UK, PhilippinesEquus subsidiaries may act as sub-processors for the provision of the services.
MailgunUS (to move to EU)Processing inbound and outbound email messages which may contain personal information. Data stored for 1 day then deleted.

Need our security pack?

DPA, sub-processor list, audit roadmap, and current controls evidence — all available on request.