Teramot — Compliance & Security
Teramot — Compliance & Security

Executive Summary
- SOC 2 Type I audit – Successfully completed with a U.S. auditing firm. Teramot has obtained its first SOC 2 report, covering the Security criteria. December 2025.

- SOC 2 Type II audit – Observation period in progress as part of the path to our SOC 2 Type II report.
- ISO 27001 documentation & evidence – currently underway (Vanta sync in progress).
- Compliance monitoring – supported by Vanta, our continuous compliance facilitator. Vanta continuously monitors our attack surface, infrastructure posture, and vulnerabilities, enabling timely remediation and patching.
- Recent Pentest – performed by Faraday Sec (Argentina). 15 vulnerabilities were identified and fully remediated.
Security & Development Tools


1 Company & Governance Snapshot
| Item | Detail |
|---|---|
| Legal Name | Halley LLC |
| Headquarters | Rosario, Argentina |
| U.S. Entity | Registered in Delaware |
| HQ Address | 16192 Coastal Highway, City of Lewes, Country of Sussex, DE 19958 |
| Countries Served | Argentina · United States |
| Information Security Committee | Bruno Ruyu · Lucas Uzal · Leandro Ruspini · Ezequiel Alejandro Mora · Valentín Torassa Colombero |
| Policy Approval | Approved by Valentín Torassa Colombero – Cybersecurity Analyst |
2 Compliance Posture Overview
| Framework / Report | Status | Auditor | Period | Next Review |
|---|---|---|---|---|
| SOC 2 Type I | Completed | U.S. Audit Firm | Completed audit period | Report available under NDA upon request |
| SOC 2 Type II | Observation period in progress | U.S. Audit Firm | Observation period | Report expected after observation period completion |
| ISO 27001 | Documentation & evidence in progress | — | Continuous | Target 2026 |
| Local Privacy Laws | Law 25.326 (Argentina), SOC 2 Privacy Criteria | — | Ongoing | Annual Review Q1 2026 |
3 Information Security Management System (ISMS) Highlights
For complete policy documentation, visit the policies section
| Domain | Key Control | Implementation |
|---|---|---|
| Identity & Access Management | MFA enabled across AWS, GitHub & Vanta accounts | Active |
| Cloud Security | GuardDuty, CloudTrail, WAF, and CloudWatch alerts | Continuous |
| Endpoint Protection | Bitdefender GravityZone | Active |
| Secrets & Passwords | Bitwarden vaults with MFA & org-scoped policies | Enforced |
| Encryption | All data encrypted at rest and in transit | AES-256 / TLS 1.3 |
| Vulnerability & Patch Mgmt | Continuous monitoring + remediation validated via pentests | Active |
| Compliance Monitoring | Vanta agent with AWS integration | Continuous |
| Secure Development | CI/CD with tests, Dependabot, Terraform validation, and peer review | Active |
4 Secure Software Development Life-Cycle (SSDLC)
- Feature branches with Pull Requests.
- Automated tests and CI/CD pipelines (GitHub Actions) validate each change.
- Progressive deployments to dev, stg, and prd on AWS ECS.
- Infrastructure is defined and deployed with Terraform.
- Dependabot manages security/dependency updates.
- Access protected with MFA and least-privilege IAM.
6 Data Privacy & Residency
| Domain | Detail |
|---|---|
| Hosting Region | AWS (us-east-1) |
| Processing Model | 100% cloud; no on-premises processing |
| Compliance | Law 25.326 (Argentina) and SOC 2 Privacy Criteria |
| Encryption | AES-256 at rest, TLS 1.3 in transit |
| Retention & Deletion | According to contractual and regulatory requirements |
7 Incident Response & Monitoring
| Component | Description |
|---|---|
| Detection Tools | AWS GuardDuty, CloudWatch Alarms, Bitdefender, AWS WAF |
| Response Team | Managed internally by Cybersecurity and DevOps |
| Notification | Customers are informed promptly upon validation of any security event |
| Root Cause Analysis | Documented internally and shared under NDA upon request |
8 Third-Party Risk & Pentest Results
- Independent Security Testing by Faraday Sec (Argentina), validating 15 vulnerabilities — all resolved. Reports and remediation tracking documented with continuous follow-up.
9 Revision History
| Date | Author | Role | Notes |
|---|---|---|---|
| Oct 2025 | Valentín Torassa Colombero | Cybersecurity & Compliance Analyst | Initial release of the Teramot Compliance & Security Pack |
SOC 2 Report Access
If your organization needs access to Teramot’s final SOC 2 report, you can request it by emailing security@teramot.com (subject to NDA).
Teramot – Halley LLC • Rosario / Miami • October 2025 — Version 1.0