Security & Trust

TerranPage carries the page that gets someone out of bed at 3 a.m. This is how we protect what sits behind it — what is live today, and what we do not claim.

Effective 2026-08-15

Compliance at a glance

Where our security and privacy posture stands today — no fabricated certifications. Anything marked not claimed may be future work; none of it is a commitment today.

Live today — Isolation, encryption, and delivery controls
Hard organization boundaries, encryption in transit and at rest, verified and consented destinations, and per-organization send limits. Each one is described below.
Live today — Privacy Policy
Named GDPR and CCPA / CPRA disclosures in the Privacy Policy.
Live today — DPA and sub-processor details on request
A customer-facing Data Processing Agreement and sub-processor details are available on request — contact us about legal requests.
Live today — Erasure within thirty (30) days
Account erasure and organization closure tombstone personal data on live paging and auth paths immediately, then hard-delete inside that window — subject to limited legal-retention exceptions described in the Privacy Policy.
Not claimed — SOC 2, ISO, and FedRAMP product certifications
TerranPage does not claim a product SOC 2, ISO, or FedRAMP certification, and will not publish certification marks until a formal assurance program completes.
Not claimed — Uptime SLA, multi-site availability, and cross-account DR
We do not publish a contractual uptime SLA, and we do not run multi-site high availability or a cross-account disaster-recovery copy.
Not claimed — Continuous penetration testing
We do not claim a continuous third-party penetration-testing program.

Organization isolation

Each organization is a hard boundary. Teams, alerts, contact methods, and related service data are scoped to that organization. A request that reaches for another organization's data is denied without revealing whether the target exists.

Personnel access is limited to what supporting and running the service requires, and it is logged.

Encryption and data protection

Customer data is encrypted in transit and at rest using industry-standard controls.

The data stores behind TerranPage are not public endpoints. Access is restricted to authorized service components, and to personnel under least-privilege policies.

Access control

Only authorized accounts reach TerranPage. Public self-serve signup may be gated; while it is, teams join by invitation.

We apply controls that reduce account abuse and unauthorized access, and we do not publish their implementation details.

Delivery and abuse controls

Every paging destination — email address, phone number, or device — must be verified and consented before TerranPage will send to it.

Per-organization send limits and suspension controls protect both the people on the receiving end and the delivery capacity every customer shares.

Monitoring and audit

We retain security-relevant records so we can detect abuse, investigate incidents, and account for what happened.

Organization administrators can review security-relevant activity for their own organization. Destinations, email addresses, phone numbers, and secrets are omitted from those views.

Resilience and recovery

We keep recoverable backups of production data and document restore procedures.

We run quarterly restore drills into a temporary, isolated copy to verify recoverability. Recovery is carried out by our team.

Incident response

We run an incident-response process covering detection, containment, customer notification where appropriate, and post-incident review.

Our status page is published at status.terranpage.com, and stays available during a terranpage.com outage. When an incident materially affects customer data or availability, we also notify affected customers through our support channels.

Privacy, GDPR, and CCPA

The Privacy Policy carries named GDPR and CCPA / CPRA disclosures: controller and processor roles, lawful bases, international-transfer safeguards, and California resident rights. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

Where we process customer personal data as a processor, Art. 28 terms are available on request.

Service providers

We rely on third-party providers for hosting, edge delivery, messaging, and related work. They process data only as needed to run TerranPage on our behalf.

We do not publish a public sub-processor list or name our providers publicly. Eligible customers can request provider details under appropriate confidentiality arrangements — contact us about security.

Contact and vulnerability reports

Security questions and vulnerability reports: contact us about security. Privacy and data-subject requests: contact us about privacy. Legal requests, including the DPA: contact us about legal requests.

Privacy Policy Terms of Service Request the DPA