Skip to content
Teramot — Compliance & Security

Teramot — Compliance & Security

Teramot Logo Teramot Logo

Executive Summary

  • SOC 2 Type I audit – Successfully completed with a U.S. auditing firm. Teramot has obtained its first SOC 2 report, covering the Security criteria. December 2025.
SOC 2
  • SOC 2 Type II audit – Observation period in progress as part of the path to our SOC 2 Type II report.
  • ISO 27001 documentation & evidence – currently underway (Vanta sync in progress).
  • Compliance monitoring – supported by Vanta, our continuous compliance facilitator. Vanta continuously monitors our attack surface, infrastructure posture, and vulnerabilities, enabling timely remediation and patching.
  • Recent Pentest – performed by Faraday Sec (Argentina). 15 vulnerabilities were identified and fully remediated.

Security & Development Tools

Faraday Sec Faraday Sec SOC 2 Vanta Bitdefender
AWS WAF AWS GuardDuty CloudWatch Terraform Bitwarden Dependabot

1 Company & Governance Snapshot

ItemDetail
Legal NameHalley LLC
HeadquartersRosario, Argentina
U.S. EntityRegistered in Delaware
HQ Address16192 Coastal Highway, City of Lewes, Country of Sussex, DE 19958
Countries ServedArgentina · United States
Information Security CommitteeBruno Ruyu · Lucas Uzal · Leandro Ruspini · Ezequiel Alejandro Mora · Valentín Torassa Colombero
Policy ApprovalApproved by Valentín Torassa Colombero – Cybersecurity Analyst

2 Compliance Posture Overview

Framework / ReportStatusAuditorPeriodNext Review
SOC 2 Type ICompletedU.S. Audit FirmCompleted audit periodReport available under NDA upon request
SOC 2 Type IIObservation period in progressU.S. Audit FirmObservation periodReport expected after observation period completion
ISO 27001Documentation & evidence in progress—ContinuousTarget 2026
Local Privacy LawsLaw 25.326 (Argentina), SOC 2 Privacy Criteria—OngoingAnnual Review Q1 2026

3 Information Security Management System (ISMS) Highlights

For complete policy documentation, visit the policies section

DomainKey ControlImplementation
Identity & Access ManagementMFA enabled across AWS, GitHub & Vanta accountsActive
Cloud SecurityGuardDuty, CloudTrail, WAF, and CloudWatch alertsContinuous
Endpoint ProtectionBitdefender GravityZoneActive
Secrets & PasswordsBitwarden vaults with MFA & org-scoped policiesEnforced
EncryptionAll data encrypted at rest and in transitAES-256 / TLS 1.3
Vulnerability & Patch MgmtContinuous monitoring + remediation validated via pentestsActive
Compliance MonitoringVanta agent with AWS integrationContinuous
Secure DevelopmentCI/CD with tests, Dependabot, Terraform validation, and peer reviewActive

4 Secure Software Development Life-Cycle (SSDLC)

  1. Feature branches with Pull Requests.
  2. Automated tests and CI/CD pipelines (GitHub Actions) validate each change.
  3. Progressive deployments to dev, stg, and prd on AWS ECS.
  4. Infrastructure is defined and deployed with Terraform.
  5. Dependabot manages security/dependency updates.
  6. Access protected with MFA and least-privilege IAM.

6 Data Privacy & Residency

DomainDetail
Hosting RegionAWS (us-east-1)
Processing Model100% cloud; no on-premises processing
ComplianceLaw 25.326 (Argentina) and SOC 2 Privacy Criteria
EncryptionAES-256 at rest, TLS 1.3 in transit
Retention & DeletionAccording to contractual and regulatory requirements

7 Incident Response & Monitoring

ComponentDescription
Detection ToolsAWS GuardDuty, CloudWatch Alarms, Bitdefender, AWS WAF
Response TeamManaged internally by Cybersecurity and DevOps
NotificationCustomers are informed promptly upon validation of any security event
Root Cause AnalysisDocumented internally and shared under NDA upon request

8 Third-Party Risk & Pentest Results

  • Independent Security Testing by Faraday Sec (Argentina), validating 15 vulnerabilities — all resolved. Reports and remediation tracking documented with continuous follow-up.

9 Revision History

DateAuthorRoleNotes
Oct 2025Valentín Torassa ColomberoCybersecurity & Compliance AnalystInitial release of the Teramot Compliance & Security Pack

SOC 2 Report Access

If your organization needs access to Teramot’s final SOC 2 report, you can request it by emailing security@teramot.com (subject to NDA).


Teramot – Halley LLC • Rosario / Miami • October 2025 — Version 1.0