Security & Data Sovereignty
Terraa is engineered for buyers who can't accept a one-size fits-all data posture: regulated family offices, DIFC / ADGM operators, European landlords under GDPR, and enterprise PM firms under SOC 2 review. Data sovereignty isn't a premium tier — it's the default.
Six defensive layers
Route document uploads to your own Google Drive, OneDrive, SharePoint, or Dropbox. Tenants upload directly to your provider — Terraa stores only a file reference and hash. For customers who want Terraa in the loop for AI and workflow automation, Connected BYO holds a narrow-scope OAuth token scoped to a dedicated folder you name.
Pick the region your structured data lives in. Terraa deploys against regional database clusters so your lease, tenant, payment, and maintenance records stay within your chosen jurisdiction — meeting local data protection laws without carving out a custom tenant.
AES-256 encryption at rest on every backing store. TLS 1.3 on every request. API keys and provider credentials encrypted with per-tenant keys. Sensitive fields (IDs, bank details, passport numbers) tokenised at the data layer with role-gated reveal.
Every table in Terraa enforces Row-Level Security at the database layer. A PM user cannot physically read another operator's records — even through a misconfigured API call. Six automated invariant tests in CI prevent regressions.
No public document URLs, ever. Every upload and every download happens through a short-lived signed token — generated only after access rights are re-verified at the API boundary. Revoked the moment access rights change.
Session management through NextAuth with optional TOTP MFA. Every privileged action writes a signed audit record. Account lockout on repeated failures. Session invalidation on password change or role change.
Regulatory coverage
Every country config carries its own tenancy law, deposit cap, notice period, data-retention, and consent-management rules — mapped through a single CountryConfig contract. The platform obeys local law automatically.
UAE & GCC
UAE PDPL, DIFC Data Protection Law 2020, ADGM Data Protection Regulations, Saudi PDPA, Qatar PDPPL, Bahrain PDPL.
EU & UK
GDPR, UK GDPR, ePrivacy Directive, country-specific implementations (BDSG, CNIL, LOPDGDD, and others).
Asia-Pacific
Singapore PDPA, Hong Kong PDPO, India DPDPA, Australia Privacy Act, Japan APPI, Malaysia PDPA.
Americas
California CCPA/CPRA, Canada PIPEDA and provincial laws, sector-specific rules where applicable.
Africa
South Africa POPIA, Nigeria NDPR, Kenya DPA — regional coverage aligned to local regulators.
Audits and attestations
SOC 2 Type II on the roadmap. Independent penetration testing planned pre-GA. Annual third-party architecture review.
Enterprise and Platform tier customers can scope a dedicated deployment with the security team — covering region selection (including the UAE / GCC roadmap path to AWS me-south-1 for full UAE PDPL residency), key-management posture, and network-isolation requirements. Specifics — KMS-managed keys, private network peering, single-tenant infrastructure — are scoped per customer based on what your compliance and procurement team need to sign.
Talk to sales