Security & Data Sovereignty
Engineered for buyers who can't accept a one-size-fits-all data posture: family offices, DIFC and ADGM operators, European landlords under GDPR. Data sovereignty is the default, not a premium tier.
Six defensive layers
Route uploads to your own Google Drive, OneDrive, SharePoint or Dropbox. Tenants upload directly to your provider and Terraa keeps only a reference and hash — or hold a narrow-scope token if you want AI in the loop.
Pick the region your structured data lives in. Terraa deploys against regional database clusters so your lease, tenant, payment, and maintenance records stay within your chosen jurisdiction — meeting local data protection laws without carving out a custom tenant.
AES-256 encryption at rest on every backing store. TLS 1.3 on every request. API keys and provider credentials encrypted with per-tenant keys. Sensitive fields (IDs, bank details, passport numbers) tokenised at the data layer with role-gated reveal.
Every table in Terraa enforces Row-Level Security at the database layer. A PM user cannot physically read another operator's records — even through a misconfigured API call. Six automated invariant tests in CI prevent regressions.
No public document URLs, ever. Every upload and every download happens through a short-lived signed token — generated only after access rights are re-verified at the API boundary. Revoked the moment access rights change.
Session management through NextAuth with optional TOTP MFA. Every privileged action writes a signed audit record. Account lockout on repeated failures. Session invalidation on password change or role change.
Regulatory coverage
Every country config carries its own tenancy law, deposit cap, notice period, data-retention, and consent-management rules — mapped through a single CountryConfig contract. The platform obeys local law automatically.
UAE & GCC
UAE PDPL, DIFC Data Protection Law 2020, ADGM Data Protection Regulations, Saudi PDPA, Qatar PDPPL, Bahrain PDPL.
EU & UK
GDPR, UK GDPR, ePrivacy Directive, country-specific implementations (BDSG, CNIL, LOPDGDD, and others).
Asia-Pacific
Singapore PDPA, Hong Kong PDPO, India DPDPA, Australia Privacy Act, Japan APPI, Malaysia PDPA.
Americas
California CCPA/CPRA, Canada PIPEDA and provincial laws, sector-specific rules where applicable.
Africa
South Africa POPIA, Nigeria NDPR, Kenya DPA — regional coverage aligned to local regulators.
Audits and attestations
SOC 2 Type II on the roadmap. Independent penetration testing planned pre-GA. Annual third-party architecture review.
Enterprise and Platform customers can scope a dedicated deployment with the security team — region selection, key management and network isolation, sized to what your compliance and procurement teams need to sign.
Talk to sales