Security

Terasu safeguards your business data with multiple layers of security controls so you can collaborate with confidence.

Encryption in transit

All traffic to Terasu is encrypted with TLS (Transport Layer Security) to prevent interception or tampering by third parties.

Data protection

  • Data at rest is encrypted with AES-256
  • Database access is restricted to our application servers
  • Regular backups support recovery in the event of an incident

Authentication and access control

  • Secure OAuth 2.0 authentication flow
  • Role-based access control (RBAC) grants appropriate permissions per user
  • Fine-grained access management at the room level

Infrastructure

  • Operated on a reliable cloud infrastructure
  • Network-level firewalls and intrusion detection
  • Logging and monitoring of access events

Development process

  • Mandatory code review
  • Regular vulnerability scans of dependencies
  • Security practices aligned with the OWASP Top 10

Security for third-party integrations

Integrations with external services like LINE and Slack use each provider's OAuth authentication and request only the minimum permissions needed. Tokens are encrypted at rest, and you can revoke any integration at any time.

Reporting vulnerabilities

If you discover a security vulnerability in Terasu, please report it to the address below. We appreciate responsible disclosure.

Security report contact

support@koromo.io

Security | Terasu