Verified controls and boundaries
Security
Verified security boundaries for the Terrain AI Labs marketing site and the human-control approach used when scoping client systems.
Last updated July 22, 2026
This marketing site
The public site is a Next.js application hosted on Vercel. It has no user accounts, database, client portal, or hosted lead-form endpoint. Internal development and test routes are request-gated and return 404 in production.
What not to send
Do not send passwords, API keys, customer records, health information, payment data, production credentials, or other confidential material through an initial email. Describe the workflow first. Secure access requirements are scoped before sensitive systems or data are used.
Client-system approach
Security requirements are specific to each engagement. Terrain scopes permissions, data access, consequential actions, human approval, testing, handoff, and production responsibility in the project agreement and technical design. This page does not promise controls that have not been implemented for a particular system.
No fabricated certifications
Terrain does not claim SOC 2, HIPAA compliance, GDPR certification, penetration-test status, an uptime SLA, or another certification through this page.
Report a concern
Email hello@terrainailabs.com with a concise description and a safe way to reproduce the issue. Do not include secrets or exploit customer data.
Questions
Plain-English answers, from a person
If something here is unclear or does not match your experience of the site, tell us. We would rather correct it than hide behind policy language.