Trust center

Evidence before promises.

Tervane separates implemented controls from configuration-dependent documents and attestations that do not exist yet.

Implemented
3
Configuration-dependent
1
Not attested
2

Implemented controls

Identity

Workspace SSO, domain claim, SCIM, custom roles, and server-enforced policy checks.

Security evidence

Release

Release decisions bind immutable artifact, browser, migration, provider-target, and source-commit evidence.

Release evidence

Data

Retention, legal hold, audit export, SIEM delivery, model/data rules, and regional targets.

Privacy evidence

Limits and dependencies

Legal

configuration-dependent

The public DPA remains a draft until company and transfer details are completed.

Availability

not-attested

No public uptime SLA or independent public status monitor is claimed.

Assurance

not-attested

No SOC 2, ISO 27001, or current independent penetration-test attestation is claimed.

Self-serve security review

Review policies and disclosures at your own pace.