TerraAqua Legal Centre

Security Policy

Document IDTA-LC-010
Version1.0
Effective date21 July 2026
Last reviewed21 July 2026
OwnerTerraAqua
ClassificationPublic

Applies to: TerraAqua websites, cloud services, applications, controller software, firmware and supporting infrastructure

1. Purpose

This policy summarises TerraAqua's approach to protecting customer information, ReefCore Controllers, TerraAqua Cloud, applications, websites and supporting infrastructure.

2. Security principles

TerraAqua applies proportionate technical and organisational measures based on risk, product design and legal requirements. Security is treated as an ongoing process rather than a one-time activity.

3. Access control

Access to production systems and personal information is restricted to authorised personnel and service providers who require access for legitimate operational purposes. Access permissions are reviewed and removed when no longer required.

4. Authentication

TerraAqua uses authentication controls to protect customer and administrative access. Customers are responsible for choosing strong passwords, protecting credentials and notifying TerraAqua if compromise is suspected.

5. Encryption

TerraAqua uses encrypted communications where appropriate, including HTTPS and other secure transport mechanisms for supported cloud and application connections. Encryption at rest is applied where proportionate to the risk and system design.

6. Software and firmware security

TerraAqua develops and maintains software and firmware with security in mind. Security fixes may be delivered through controller, application, website or cloud updates. Customers should install important updates promptly.

7. Controller architecture

ReefCore is designed to support local operation where possible. Cloud services are separated from core local controller operation so that temporary loss of internet connectivity does not necessarily stop local monitoring and control.

8. Network security

TerraAqua uses network segmentation, firewalls, access restrictions and monitoring where appropriate. Customers should secure their own home or business networks, routers, Wi-Fi credentials and connected third-party equipment.

9. Logging and monitoring

TerraAqua may record security, authentication, operational and diagnostic events to detect faults, abuse and suspicious activity. Logs are retained only for as long as reasonably necessary for their purpose and legal obligations.

10. Data minimisation

TerraAqua aims to collect and retain only the information reasonably required to provide, secure and improve its products and services. Personal information is handled in accordance with the Privacy Policy.

11. Service providers

Where third-party hosting, payment, communications or infrastructure providers are used, TerraAqua selects providers with appropriate security measures and contracts where required.

12. Backups and resilience

TerraAqua uses backups and recovery measures appropriate to the relevant service. No backup system can guarantee that every item of data will always be recoverable. Customers remain responsible for their own records and safe aquarium-operation arrangements.

13. Vulnerability management

Reported or discovered vulnerabilities are assessed according to severity, exploitability and impact. TerraAqua may develop, test and deploy fixes, mitigations or customer guidance as appropriate.

14. Security testing

TerraAqua may conduct code review, dependency review, configuration checks, vulnerability scanning and other security testing appropriate to the product or service.

15. Incident response

Suspected security incidents are investigated and contained as appropriate. TerraAqua may reset credentials, suspend access, deploy emergency updates, preserve evidence and work with specialist providers or authorities.

16. Notifications

Where an incident creates a legal obligation to notify affected individuals or a regulator, TerraAqua will make the notification within the applicable timeframe and provide available information about the incident and recommended action.

17. Customer security responsibilities

Customers should:

18. Limits

No system can be guaranteed completely secure. TerraAqua cannot protect against compromise caused by weak customer credentials, unsupported modification, unsafe network configuration, malware on customer devices or third-party services outside TerraAqua's control.

19. Reporting security concerns

Security concerns and suspected vulnerabilities should be reported under the Vulnerability Disclosure Policy.

20. Contact

Security enquiries may be sent to info@terra-aqua.co.uk.

Version history

VersionDateDescription
1.021 July 2026Initial commercial release