Legal
Privacy Policy
This policy explains how Terra Ops handles account identity, AWS credentials, session data, and generated platform outputs in a trust-first product model.
Last updated: 14 August 2026 · Effective immediatelyReview-readyTrust artifact
On this page
MetadataScan-friendly review cues
Credential handling
AWS credentials are used only for read-only assessments and are described as encrypted at rest with AES-256 protections.
Authentication posture
Account access is built around password authentication plus mandatory TOTP-based 2FA.
Data isolation
Isolated per user, or per organization when you belong to one — administrators and managers of your organization can see its activity. Never shared outside it.
Retention posture
Account data persists while active, while credentials and scan records remain user-removable through the platform lifecycle.
Trust highlightsWhat reviewers usually look for first
✓Read-only AWS credential usage is explicitly documented rather than implied.
✓Authentication and session behavior are called out as part of the security posture, not just account mechanics.
✓The policy states no sale or third-party sharing of personal information outside narrow legal or transfer scenarios.
✓Reviewers can quickly find encryption, access control, retention, and rights language from the summary layer first.
1. Introduction
Terra Ops ("we", "our", or "the Platform") is a cloud security assessment platform developed and maintained by Sumit Bhadu — CKA, AZ-104, AZ-305 & MLOps certified (GitHub: sumit-bhadu). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, including our web application, APIs, and associated services.
By accessing or using Terra Ops, you agree to the collection and use of information as described in this policy. If you disagree with any part of this policy, please discontinue use of the platform immediately.
By accessing or using Terra Ops, you agree to the collection and use of information as described in this policy. If you disagree with any part of this policy, please discontinue use of the platform immediately.
2. Information We Collect
2.1 Account Information
When you register, we collect your email address, full name (optional), and a hashed password. We also store your time-based one-time password (TOTP) secret for two-factor authentication. We never store your TOTP codes — only the shared secret used to verify them.
2.2 AWS Credentials
To perform security assessments, you provide AWS credentials (Access Key ID and Secret Access Key) or an IAM Role ARN. These credentials are encrypted at rest using AES-256 and are used exclusively to perform read-only security scans against your AWS account. We never use your credentials for any other purpose, never sell them, and never transmit them to third parties.
2.3 Scan Data and Findings
Security scan results, compliance reports, cost data, and infrastructure diagrams are stored in your account database. This data is never sold or shared with third parties. If you belong to an organization, it is shared within that organization: the cloud accounts you connect belong to the organization, and administrators of that organization can see the scans and findings produced against them. See 2.5. If you do not belong to an organization, your data is visible only to you.
2.4 Usage Data
We do not operate any behavioural or product-analytics telemetry. There is no third-party analytics SDK in this application, and no record of which pages you visit or which buttons you press is sent anywhere.
2.5 Activity and Audit Records
Terra Ops keeps an audit trail, and it is deliberately not anonymous. Because this is a security product, an organization has to be able to establish who did what — so actions taken in the platform are recorded against the individual who took them.
Each record contains: the action performed and whether it was allowed or refused, the account or resource it concerned, your user id and your role at the time, the organization the action belonged to, the originating IP address, your browser's user-agent string, a correlation id linking the action to our server logs, and, for changes, the before and after values of what changed. Refusals are recorded as well as successes.
Who can see it. Administrators and managers of your organization can read the audit trail for your organization, including your activity — both roles carry that permission by default. They can also open the results of scans you run against your organization's cloud accounts, which is what lets a manager review work before it is shared; that access is itself recorded, so an administrator can see who read what. This is the point of the feature: an organization is accountable for what its members do with its cloud credentials. Ordinary members cannot read anyone else's activity or results. Terra Ops staff can see that an organization exists and how large it is; the platform view available to us reports counts, not the contents of your scans, findings, or activity.
Account actions by Terra Ops. As the platform operator we can lock or remove an account, or remove an account from an organization, where that is needed to protect the platform or to meet a legal obligation. Each action is recorded with a stated reason. It does not give us access to the contents of your data, and we cannot reset your password.
How long. Audit records are retained for one year, after which they are deleted. Deletion happens in monthly batches, so a record may persist for up to a month past that point before its batch is removed. Retention is currently the same for every organization and is not adjustable from within the product; if your organization needs a different period, contact us. Records are not editable through the product by anyone, including us.
High-frequency automatic requests — a page polling a running scan for progress, for example — are deliberately excluded, because recording them would bury the actions a person actually took.
2.6 Sign-in Records
Separately from the audit trail, we keep a record of sign-in attempts on your own account — successful and failed — so that you can see them. Each entry holds the time, the IP address the attempt came from, your browser's user-agent string, whether it succeeded, and if it did not, why. You can read your own at any time on your account page. This record is yours: it is not shown to your organization's administrators, who see sign-in events through the audit trail described above instead.
Where a sign-in came from. We show an approximate location next to each entry so an unfamiliar sign-in is recognisable as unfamiliar. It is derived inside our own infrastructure, by looking your IP address up in a geolocation database that ships with our software. Your IP address is not sent to a geolocation service or to any other third party in order to produce it. The result is approximate — it identifies a city or region, not a place — and it is stored alongside the entry so that the list still reads correctly later.
How long. Sign-in records are kept for 90 days and then deleted.
When you register, we collect your email address, full name (optional), and a hashed password. We also store your time-based one-time password (TOTP) secret for two-factor authentication. We never store your TOTP codes — only the shared secret used to verify them.
2.2 AWS Credentials
To perform security assessments, you provide AWS credentials (Access Key ID and Secret Access Key) or an IAM Role ARN. These credentials are encrypted at rest using AES-256 and are used exclusively to perform read-only security scans against your AWS account. We never use your credentials for any other purpose, never sell them, and never transmit them to third parties.
2.3 Scan Data and Findings
Security scan results, compliance reports, cost data, and infrastructure diagrams are stored in your account database. This data is never sold or shared with third parties. If you belong to an organization, it is shared within that organization: the cloud accounts you connect belong to the organization, and administrators of that organization can see the scans and findings produced against them. See 2.5. If you do not belong to an organization, your data is visible only to you.
2.4 Usage Data
We do not operate any behavioural or product-analytics telemetry. There is no third-party analytics SDK in this application, and no record of which pages you visit or which buttons you press is sent anywhere.
2.5 Activity and Audit Records
Terra Ops keeps an audit trail, and it is deliberately not anonymous. Because this is a security product, an organization has to be able to establish who did what — so actions taken in the platform are recorded against the individual who took them.
Each record contains: the action performed and whether it was allowed or refused, the account or resource it concerned, your user id and your role at the time, the organization the action belonged to, the originating IP address, your browser's user-agent string, a correlation id linking the action to our server logs, and, for changes, the before and after values of what changed. Refusals are recorded as well as successes.
Who can see it. Administrators and managers of your organization can read the audit trail for your organization, including your activity — both roles carry that permission by default. They can also open the results of scans you run against your organization's cloud accounts, which is what lets a manager review work before it is shared; that access is itself recorded, so an administrator can see who read what. This is the point of the feature: an organization is accountable for what its members do with its cloud credentials. Ordinary members cannot read anyone else's activity or results. Terra Ops staff can see that an organization exists and how large it is; the platform view available to us reports counts, not the contents of your scans, findings, or activity.
Account actions by Terra Ops. As the platform operator we can lock or remove an account, or remove an account from an organization, where that is needed to protect the platform or to meet a legal obligation. Each action is recorded with a stated reason. It does not give us access to the contents of your data, and we cannot reset your password.
How long. Audit records are retained for one year, after which they are deleted. Deletion happens in monthly batches, so a record may persist for up to a month past that point before its batch is removed. Retention is currently the same for every organization and is not adjustable from within the product; if your organization needs a different period, contact us. Records are not editable through the product by anyone, including us.
High-frequency automatic requests — a page polling a running scan for progress, for example — are deliberately excluded, because recording them would bury the actions a person actually took.
2.6 Sign-in Records
Separately from the audit trail, we keep a record of sign-in attempts on your own account — successful and failed — so that you can see them. Each entry holds the time, the IP address the attempt came from, your browser's user-agent string, whether it succeeded, and if it did not, why. You can read your own at any time on your account page. This record is yours: it is not shown to your organization's administrators, who see sign-in events through the audit trail described above instead.
Where a sign-in came from. We show an approximate location next to each entry so an unfamiliar sign-in is recognisable as unfamiliar. It is derived inside our own infrastructure, by looking your IP address up in a geolocation database that ships with our software. Your IP address is not sent to a geolocation service or to any other third party in order to produce it. The result is approximate — it identifies a city or region, not a place — and it is stored alongside the entry so that the list still reads correctly later.
How long. Sign-in records are kept for 90 days and then deleted.
3. How We Use Your Information
We use the information we collect to:
• Provide, operate, and maintain the Terra Ops platform
• Authenticate your identity and protect your account
• Run AWS security assessments on your behalf using your credentials
• Generate compliance reports, threat intelligence, and architecture diagrams
• Send account-related communications (security alerts, account updates)
• Improve platform performance, reliability, and security
• Comply with legal obligations
• Provide, operate, and maintain the Terra Ops platform
• Authenticate your identity and protect your account
• Run AWS security assessments on your behalf using your credentials
• Generate compliance reports, threat intelligence, and architecture diagrams
• Send account-related communications (security alerts, account updates)
• Improve platform performance, reliability, and security
• Comply with legal obligations
4. Data Storage and Security
4.1 Encryption at Rest
All sensitive data — including AWS credentials, passwords, and TOTP secrets — is encrypted at rest using AES-256 encryption. Passwords are hashed using bcrypt with a per-user salt and are never stored in plaintext.
4.2 Encryption in Transit
All communication between your browser and Terra Ops servers is encrypted using TLS 1.2 or higher. API endpoints are protected by HTTPS-only policies.
4.3 Access Controls
Isolation is enforced in the application: every request is authenticated, and every query that reads your data is filtered by your user id, or by your organization when you belong to one. Access to another user's data outside your organization is not possible through any endpoint, and a dedicated test suite exists to keep it that way. Within an organization, what each role may see is described in 2.5. Database credentials are held only by the platform's own services, injected as Kubernetes secrets, and are never exposed to browsers or to customers.
4.4 Two-Factor Authentication
All Terra Ops accounts require TOTP-based two-factor authentication. This is enforced at registration and cannot be disabled, ensuring that even if your password is compromised, your account remains protected.
All sensitive data — including AWS credentials, passwords, and TOTP secrets — is encrypted at rest using AES-256 encryption. Passwords are hashed using bcrypt with a per-user salt and are never stored in plaintext.
4.2 Encryption in Transit
All communication between your browser and Terra Ops servers is encrypted using TLS 1.2 or higher. API endpoints are protected by HTTPS-only policies.
4.3 Access Controls
Isolation is enforced in the application: every request is authenticated, and every query that reads your data is filtered by your user id, or by your organization when you belong to one. Access to another user's data outside your organization is not possible through any endpoint, and a dedicated test suite exists to keep it that way. Within an organization, what each role may see is described in 2.5. Database credentials are held only by the platform's own services, injected as Kubernetes secrets, and are never exposed to browsers or to customers.
4.4 Two-Factor Authentication
All Terra Ops accounts require TOTP-based two-factor authentication. This is enforced at registration and cannot be disabled, ensuring that even if your password is compromised, your account remains protected.
5. Data Sharing and Disclosure
We do not sell, trade, rent, or share your personal information with third parties, except in the following limited circumstances:
Legal Requirements: We may disclose information if required by law, court order, or government authority.
Security Incidents: If we detect unauthorised access or a breach affecting your data, we will notify you promptly.
Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
Legal Requirements: We may disclose information if required by law, court order, or government authority.
Security Incidents: If we detect unauthorised access or a breach affecting your data, we will notify you promptly.
Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
6. AWS Credential Handling
Terra Ops takes AWS credential security extremely seriously. Your credentials are:
• Stored encrypted using AES-256 with per-credential encryption keys
• Used only for read-only AWS API calls during security assessments
• Never logged in plaintext in application logs or error messages
• Accessible only by authenticated API requests from your own session
• Deletable at any time — deleting an account removes all associated credentials
We strongly recommend using IAM roles with read-only policies rather than root credentials. See our documentation for the minimum required IAM permissions.
• Stored encrypted using AES-256 with per-credential encryption keys
• Used only for read-only AWS API calls during security assessments
• Never logged in plaintext in application logs or error messages
• Accessible only by authenticated API requests from your own session
• Deletable at any time — deleting an account removes all associated credentials
We strongly recommend using IAM roles with read-only policies rather than root credentials. See our documentation for the minimum required IAM permissions.
7. Data Retention
Account Data: Retained while your account is active. Deleted within 30 days of account deletion.
Scan Results: Retained indefinitely in your account until manually deleted. You can delete individual scans from the platform at any time.
AWS Credentials: Retained until you delete the associated cloud account from the platform.
Session Data: Sessions are signed out after 60 minutes of inactivity, and refresh credentials expire on their configured lifetime. Session cookies are automatically invalidated on logout.
Activity and Audit Records: Retained for one year, then deleted in monthly batches (see 2.5). If you belong to an organization, these records form part of that organization's accountability record: they name you, and they are not removed when you leave the organization or delete your account. They expire on the retention period above.
Scan Results: Retained indefinitely in your account until manually deleted. You can delete individual scans from the platform at any time.
AWS Credentials: Retained until you delete the associated cloud account from the platform.
Session Data: Sessions are signed out after 60 minutes of inactivity, and refresh credentials expire on their configured lifetime. Session cookies are automatically invalidated on logout.
Activity and Audit Records: Retained for one year, then deleted in monthly batches (see 2.5). If you belong to an organization, these records form part of that organization's accountability record: they name you, and they are not removed when you leave the organization or delete your account. They expire on the retention period above.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
• Access: Request a copy of all personal data we hold about you
• Correction: Update or correct inaccurate personal information
• Deletion: Request deletion of your account and all associated data. One exception, stated plainly: if you belong to an organization, the audit records of what you did with that organization's cloud credentials are part of its accountability record and are retained for the period in 2.5 rather than deleted with your account. Everything else — your identity, credentials, scans, reports and sessions — is deleted
• Portability: Export your scan data in machine-readable formats (PDF, DOCX, JSON)
• Objection: Object to specific processing of your data
To exercise any of these rights, contact us via GitHub: github.com/sumit-bhadu
• Access: Request a copy of all personal data we hold about you
• Correction: Update or correct inaccurate personal information
• Deletion: Request deletion of your account and all associated data. One exception, stated plainly: if you belong to an organization, the audit records of what you did with that organization's cloud credentials are part of its accountability record and are retained for the period in 2.5 rather than deleted with your account. Everything else — your identity, credentials, scans, reports and sessions — is deleted
• Portability: Export your scan data in machine-readable formats (PDF, DOCX, JSON)
• Objection: Object to specific processing of your data
To exercise any of these rights, contact us via GitHub: github.com/sumit-bhadu
9. Cookies and Session Storage
Terra Ops uses:
• Session Cookie (`terraops_session`): An HTTP-only, secure, SameSite=Lax cookie used for authentication. This is strictly necessary and cannot be disabled.
• SessionStorage: Used to remember your last navigation destination for post-login redirect. Contains no personal data and is cleared on browser close.
We do not use tracking cookies, advertising cookies, or any third-party analytics cookies.
This section is about cookies and browser storage, and it says nothing about the audit trail described in section 2.5 — which is server-side, first-party, attributable to you by name, and readable by administrators of your organization. Neither statement qualifies the other; read both.
• Session Cookie (`terraops_session`): An HTTP-only, secure, SameSite=Lax cookie used for authentication. This is strictly necessary and cannot be disabled.
• SessionStorage: Used to remember your last navigation destination for post-login redirect. Contains no personal data and is cleared on browser close.
We do not use tracking cookies, advertising cookies, or any third-party analytics cookies.
This section is about cookies and browser storage, and it says nothing about the audit trail described in section 2.5 — which is server-side, first-party, attributable to you by name, and readable by administrators of your organization. Neither statement qualifies the other; read both.
10. Children's Privacy
Terra Ops is intended for professional use by security engineers, DevOps teams, and cloud architects. We do not knowingly collect information from anyone under the age of 16. If you believe a minor has created an account, contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the platform interface. Your continued use of Terra Ops after changes take effect constitutes acceptance of the updated policy. The effective date at the top of this page indicates when the policy was last revised.
12. Contact
For privacy questions, data requests, or security concerns, please contact us:
• GitHub: github.com/sumit-bhadu
• Project Repository: github.com/sumit-bhadu/terra-ops
We aim to respond to all privacy inquiries within 72 hours.
• GitHub: github.com/sumit-bhadu
• Project Repository: github.com/sumit-bhadu/terra-ops
We aim to respond to all privacy inquiries within 72 hours.