The truth about how Tessarac protects your data.
Compliance status, sub-processors, security architecture, incident response, vulnerability disclosure — published in one place, updated when status changes (not when an audit closes). If you're a Tessarac customer or considering becoming one, this page is the answer to your security-team's questionnaire.
Security architecture
Envelope encryption, hardware-bound identity, IPv6-native — by default.
Tessarac's security architecture is built on three load-bearing pillars: end-to-end agent envelope encryption (even our load balancers can't read your traffic), hardware-bound TPM / Secure Enclave identity (the credential-extraction class of attack doesn't apply), and IPv6-native dual-stack networking (OMB M-21-07 alignment by default).
- End-to-end agent envelope encryption — payload wrapped at the agent, unwrapped only at the policy decision point
- Per-tenant ECDSA P-384 trust anchor with HSM / cloud-KMS / BYOK options
- Hardware-bound agent identity — private key generated inside TPM / Secure Enclave / WPCP, never leaves hardware
- IPv6-native control plane and data plane — dual-stack [::]:port listeners; AAAA records published
- Ephemeral sandbox infrastructure — pay-per-detonation, near-zero idle cost, no cross-tenant data exposure
- Tamper-evident audit log — hash-chained, exportable to your existing SIEM
Compliance status
Honest snapshot of where each framework stands today. Updated when status changes.
| Framework | Status | Notes |
|---|---|---|
| SOC 2 Type 2 | In flight | Phase 1 — observation period open; report expected end of Phase 2. Going straight to Type 2 (no Type 1 step). |
| HIPAA | Ready | Business Associate Agreement available on Business plan and above. |
| PCI-DSS v4 | Ready | Reference architecture published for cardholder-data login deployments. |
| FedRAMP High | Targeted | Phase 3 — 3PAO assessment underway; pursuing Agency Authorization with a sponsoring agency. |
| DoD IL5 | Roadmap | Phase 4 — Federal plan only, sovereign US-only or on-premises. Inherits FedRAMP High baseline. |
| CMMC 2.0 L2 | Roadmap | Phase 4 — for defense industrial base customers. |
| GDPR | Ready | Data Processing Agreement available; EU data residency on Enterprise and Federal. |
| ISO 27001:2022 | Targeted | Phase 3 — Stage 1 + Stage 2 audits scheduled with the same auditor as the SOC 2 Type 2 engagement. |
"Ready" — controls and contractual artifacts in place today. "In flight" — audit actively underway. "Targeted" — scheduled for the named phase. "Roadmap" — committed but not yet scheduled.
Sub-processor categories
The categories of sub-processors we use to operate the commercial-tier service, with data residency. The full named-vendor list (with the specific provider in each category) is published in our trust portal and shared under NDA on request. We notify customers under contract 30 days before any change.
| Category | Purpose | Data residency |
|---|---|---|
| Primary cloud infrastructure (commercial) | Compute, managed datastore, object storage | US multi-region with optional EU residency on Enterprise |
| Sovereign cloud infrastructure (federal) | FedRAMP-authorized US-only environment for the Federal plan | US sovereign region |
| Edge security and DDoS mitigation (commercial) | Multi-tier DDoS mitigation, edge WAF, AI inference gateway routing | Global edge with US residency option |
| AI inference provider (commercial) | Inference provider for the AI-empowered 24/7 SOC (commercial tier only) | US (sovereign US-only inference for federal tier) |
| Source control + CI/CD + container registry | Engineering toolchain | US |
| Commercial payment processing | Subscription billing for self-service customers | US |
| Transactional email | Outbound notifications, audit-event delivery summaries | US |
Federal-tier deployments transit no commercial-tier sub-processors; AI analysis routes through a sovereign US-only inference path inside the federal boundary. Self-hosted deployments transit nothing. For exactly what is tokenized or dropped before any alert evidence reaches the AI model, seeHow Tessarac uses your data for AI-assisted security analysis.
Incident response
We treat every customer incident as our incident. Our IR runbook ships in the trust portal; the short version is below.
- Detection
- AI-SOC Tier 1 triage on every alert; Tier 2 investigation on every escalation; on-call rotation 24x7. Alert evidence is de-identified before any model call — see theAI data-handling reference.
- Containment
- 5-tier graduated cordon; out-of-band backstop; standing-privilege-zero default.
- Customer notification
- Confirmed customer-impacting incident → notification within 24 hours per the customer agreement.
- Post-mortem
- Public post-mortem within 7 business days for every customer-visible incident; root-cause analysis with action items.
Vulnerability disclosure
We rely on the security community. If you've found something, get in touch — we'll respond fast and we don't pursue good-faith researchers.
- Where to report
- security@tessarac.com
PGP key at/.well-known/security.txt - First response
- Within 1 business day.
- Triage SLA
- CVSS 9.0+ within 24 hours. CVSS 7.0+ within 3 days.
- Patch SLA
- Critical: 24 hours (Federal) / 2 business days (every other paid plan). High: 10 business days (every paid plan, tighter on Federal by contract).
- Safe harbor
- Good-faith research that respects user privacy and doesn't disrupt service is welcomed and protected from legal action under our coordinated-disclosure policy.
Need a security questionnaire turned around?
The trust portal carries the SOC 2 narrative draft, the architecture diagrams, and the sub-processor list. Email us for the full packet.