TerralytixTERRALYTIX

Security & Trust

Your property data belongs to you

We use precise language here on purpose. We'll tell you what's actually true about our security posture, not what sounds reassuring.

Data isolation

Every table is protected by Postgres row-level security scoped to your account. Your data is not queryable by other users' sessions, by design of the database itself — not just application logic.

Encryption

Data is encrypted in transit (TLS) and at rest by our infrastructure provider. Documents are stored in a private bucket and served only via short-lived signed URLs.

Authentication & sessions

Authentication is handled by a managed identity provider. Session cookies are HTTP-only and refreshed server-side on every request.

AI and your data

You are never asked to paste an AI provider API key into Terralytix. All AI calls, when a provider is configured, are made server-side through an internal gateway — no client-side code ever holds a provider key.

Audit log

Sensitive actions — logins, document views, edits to properties, payments, and data exports — are recorded to an append-only audit log visible to you under Activity.

Data export & deletion

You can export everything Terralytix holds about your account as a single file at any time from Settings.

We do not claim formal certifications (e.g. SOC 2) or specific regulatory compliance (e.g. DPDP) until they have been independently verified. Our controls are designed with these frameworks in mind; an independent assessment is on our roadmap.