Trust Center

The truth about how Tessarac protects your data.

Compliance status, sub-processors, security architecture, incident response, vulnerability disclosure — published in one place, updated when status changes (not when an audit closes). If you're a Tessarac customer or considering becoming one, this page is the answer to your security-team's questionnaire.

Security architecture

Envelope encryption, hardware-bound identity, IPv6-native — by default.

Tessarac's security architecture is built on three load-bearing pillars: end-to-end agent envelope encryption (even our load balancers can't read your traffic), hardware-bound TPM / Secure Enclave identity (the credential-extraction class of attack doesn't apply), and IPv6-native dual-stack networking (OMB M-21-07 alignment by default).

  • End-to-end agent envelope encryption — payload wrapped at the agent, unwrapped only at the policy decision point
  • Per-tenant ECDSA P-384 trust anchor with HSM / cloud-KMS / BYOK options
  • Hardware-bound agent identity — private key generated inside TPM / Secure Enclave / WPCP, never leaves hardware
  • IPv6-native control plane and data plane — dual-stack [::]:port listeners; AAAA records published
  • Ephemeral sandbox infrastructure — pay-per-detonation, near-zero idle cost, no cross-tenant data exposure
  • Tamper-evident audit log — hash-chained, exportable to your existing SIEM

Compliance status

Honest snapshot of where each framework stands today. Updated when status changes.

FrameworkStatusNotes
SOC 2 Type 2In flightPhase 1 — observation period open; report expected end of Phase 2. Going straight to Type 2 (no Type 1 step).
HIPAAReadyBusiness Associate Agreement available on Business plan and above.
PCI-DSS v4ReadyReference architecture published for cardholder-data login deployments.
FedRAMP HighTargetedPhase 3 — 3PAO assessment underway; pursuing Agency Authorization with a sponsoring agency.
DoD IL5RoadmapPhase 4 — Federal plan only, sovereign US-only or on-premises. Inherits FedRAMP High baseline.
CMMC 2.0 L2RoadmapPhase 4 — for defense industrial base customers.
GDPRReadyData Processing Agreement available; EU data residency on Enterprise and Federal.
ISO 27001:2022TargetedPhase 3 — Stage 1 + Stage 2 audits scheduled with the same auditor as the SOC 2 Type 2 engagement.

"Ready" — controls and contractual artifacts in place today. "In flight" — audit actively underway. "Targeted" — scheduled for the named phase. "Roadmap" — committed but not yet scheduled.

Sub-processor categories

The categories of sub-processors we use to operate the commercial-tier service, with data residency. The full named-vendor list (with the specific provider in each category) is published in our trust portal and shared under NDA on request. We notify customers under contract 30 days before any change.

CategoryPurposeData residency
Primary cloud infrastructure (commercial)Compute, managed datastore, object storageUS multi-region with optional EU residency on Enterprise
Sovereign cloud infrastructure (federal)FedRAMP-authorized US-only environment for the Federal planUS sovereign region
Edge security and DDoS mitigation (commercial)Multi-tier DDoS mitigation, edge WAF, AI inference gateway routingGlobal edge with US residency option
AI inference provider (commercial)Inference provider for the AI-empowered 24/7 SOC (commercial tier only)US (sovereign US-only inference for federal tier)
Source control + CI/CD + container registryEngineering toolchainUS
Commercial payment processingSubscription billing for self-service customersUS
Transactional emailOutbound notifications, audit-event delivery summariesUS

Federal-tier deployments transit no commercial-tier sub-processors; AI analysis routes through a sovereign US-only inference path inside the federal boundary. Self-hosted deployments transit nothing. For exactly what is tokenized or dropped before any alert evidence reaches the AI model, seeHow Tessarac uses your data for AI-assisted security analysis.

Incident response

We treat every customer incident as our incident. Our IR runbook ships in the trust portal; the short version is below.

Detection
AI-SOC Tier 1 triage on every alert; Tier 2 investigation on every escalation; on-call rotation 24x7. Alert evidence is de-identified before any model call — see theAI data-handling reference.
Containment
5-tier graduated cordon; out-of-band backstop; standing-privilege-zero default.
Customer notification
Confirmed customer-impacting incident → notification within 24 hours per the customer agreement.
Post-mortem
Public post-mortem within 7 business days for every customer-visible incident; root-cause analysis with action items.

Vulnerability disclosure

We rely on the security community. If you've found something, get in touch — we'll respond fast and we don't pursue good-faith researchers.

Where to report
security@tessarac.com
PGP key at /.well-known/security.txt
First response
Within 1 business day.
Triage SLA
CVSS 9.0+ within 24 hours. CVSS 7.0+ within 3 days.
Patch SLA
Critical: 24 hours (Federal) / 2 business days (every other paid plan). High: 10 business days (every paid plan, tighter on Federal by contract).
Safe harbor
Good-faith research that respects user privacy and doesn't disrupt service is welcomed and protected from legal action under our coordinated-disclosure policy.

Need a security questionnaire turned around?

The trust portal carries the SOC 2 narrative draft, the architecture diagrams, and the sub-processor list. Email us for the full packet.