Skip to main content

How secure is the data Teramind collects and stores in the cloud?

A
Written by Arick Disilva

Teramind utilizes a robust, layered security approach to protect data in the cloud, covering both data at rest and data in motion.

  • Encryption (Data at Rest): All customer data, account credentials, logs, and backups in persistent storage are protected using strong AES 256-bit encryption.

  • Encryption (Data in Motion): All communication between the Teramind Agent/endpoints and Teramind Server uses our proprietary protocol. Teramind policy enforces that all interaction with its server happen over TLS (for Active Directory LDAP connections) or SSL (for HTTPS) with a 4-key system (private, public, intermediate, root).

  • Physical and Administrative Security: Teramind is hosted in a secure, tier-3 data center. Instances are isolated from administrators and IT staff, and procedures are in place to ensure Teramind staff cannot access customer data.

  • Access Control: Access to the Cloud production environment is strictly restricted to a minimal number of vetted personnel on a need-to-know basis (Least Privilege). All access is logged and audited. Teramind Support and Customer Success teams have no standing access to customer data. Access is only possible if explicitly granted by the customer (e.g., via a temporary Support PIN or screen share), which is also logged.

Did this answer your question?