Security
ISO 27001:2022 certified, with all production data held in India on AWS Mumbai.
Certification and alignment
What we hold, and the frameworks our controls are aligned to.
ISO 27001:2022
Certified information security management system. Annex A control notes are published on our certifications page.
View detailsDPDP Act 2023 aligned
Personal-data processing aligned with the Digital Personal Data Protection Act 2023.
View detailsRBI IT governance aligned
Controls aligned with RBI IT governance expectations for regulated-entity customers.
View detailsAWS Mumbai
Production runs exclusively in the managed AWS Mumbai data centre. No physical servers at office locations.
View detailsSecurity controls
Drawn from our ISO 27001:2022 Annex A control notes.
Encryption at rest and in transit
AES-256 for data at rest and TLS 1.2 or higher for data in transit, with key management through AWS KMS.
Multi-factor authentication
MFA is mandatory for all privileged accounts and enforced on every external-facing system and cloud management console.
Role-based access control
Access is scoped to role and client, with no cross-tenant data access. Access rights are reviewed quarterly and on every role change.
Audit log retention
Audit logs are retained for seven years in line with the regulatory minimum.
Vulnerability management
Vulnerability scans run fortnightly, with critical findings remediated within 72 hours. DAST and penetration testing run before every major release.
Encrypted daily backups
Daily encrypted backups, with restoration tested quarterly against a defined recovery time objective.
Infrastructure
Production hardware sits exclusively in the managed AWS Mumbai data centre, which is SOC 2 Type II audited and built to Tier III standards for power, cooling and environmental controls. There are no physical servers at our office locations.
Access to production is through a centralised identity provider with mandatory multi-factor authentication, under the principle of least privilege. Removable media is prohibited in production environments.
Backups are taken daily and encrypted, and restoration is tested every quarter against a defined recovery time objective.
Security Contacts
Report a vulnerability
info@terra-insight.comSecurity questionnaires
info@terra-insight.comSecurity FAQ
Common questions about our security practices.
How do you handle data encryption?
Where is my data stored?
Which certifications do you hold?
How do you test your security?
What happens in case of a security incident?
Can I request a security questionnaire or assessment?
Need more information?
Talk to us about your security review, questionnaire or documentation requirements.