Security Policy
Applies to: TerraAqua websites, cloud services, applications, controller software, firmware and supporting infrastructure
1. Purpose
This policy summarises TerraAqua's approach to protecting customer information, ReefCore Controllers, TerraAqua Cloud, applications, websites and supporting infrastructure.
2. Security principles
TerraAqua applies proportionate technical and organisational measures based on risk, product design and legal requirements. Security is treated as an ongoing process rather than a one-time activity.
3. Access control
Access to production systems and personal information is restricted to authorised personnel and service providers who require access for legitimate operational purposes. Access permissions are reviewed and removed when no longer required.
4. Authentication
TerraAqua uses authentication controls to protect customer and administrative access. Customers are responsible for choosing strong passwords, protecting credentials and notifying TerraAqua if compromise is suspected.
5. Encryption
TerraAqua uses encrypted communications where appropriate, including HTTPS and other secure transport mechanisms for supported cloud and application connections. Encryption at rest is applied where proportionate to the risk and system design.
6. Software and firmware security
TerraAqua develops and maintains software and firmware with security in mind. Security fixes may be delivered through controller, application, website or cloud updates. Customers should install important updates promptly.
7. Controller architecture
ReefCore is designed to support local operation where possible. Cloud services are separated from core local controller operation so that temporary loss of internet connectivity does not necessarily stop local monitoring and control.
8. Network security
TerraAqua uses network segmentation, firewalls, access restrictions and monitoring where appropriate. Customers should secure their own home or business networks, routers, Wi-Fi credentials and connected third-party equipment.
9. Logging and monitoring
TerraAqua may record security, authentication, operational and diagnostic events to detect faults, abuse and suspicious activity. Logs are retained only for as long as reasonably necessary for their purpose and legal obligations.
10. Data minimisation
TerraAqua aims to collect and retain only the information reasonably required to provide, secure and improve its products and services. Personal information is handled in accordance with the Privacy Policy.
11. Service providers
Where third-party hosting, payment, communications or infrastructure providers are used, TerraAqua selects providers with appropriate security measures and contracts where required.
12. Backups and resilience
TerraAqua uses backups and recovery measures appropriate to the relevant service. No backup system can guarantee that every item of data will always be recoverable. Customers remain responsible for their own records and safe aquarium-operation arrangements.
13. Vulnerability management
Reported or discovered vulnerabilities are assessed according to severity, exploitability and impact. TerraAqua may develop, test and deploy fixes, mitigations or customer guidance as appropriate.
14. Security testing
TerraAqua may conduct code review, dependency review, configuration checks, vulnerability scanning and other security testing appropriate to the product or service.
15. Incident response
Suspected security incidents are investigated and contained as appropriate. TerraAqua may reset credentials, suspend access, deploy emergency updates, preserve evidence and work with specialist providers or authorities.
16. Notifications
Where an incident creates a legal obligation to notify affected individuals or a regulator, TerraAqua will make the notification within the applicable timeframe and provide available information about the incident and recommended action.
17. Customer security responsibilities
Customers should:
- use unique, strong passwords;
- protect email and TerraAqua account access;
- keep controllers, applications and devices updated;
- avoid exposing local controller interfaces directly to the public internet;
- use trusted network equipment and suitable firewall settings;
- remove account access before transferring hardware; and
- report suspicious activity promptly.
18. Limits
No system can be guaranteed completely secure. TerraAqua cannot protect against compromise caused by weak customer credentials, unsupported modification, unsafe network configuration, malware on customer devices or third-party services outside TerraAqua's control.
19. Reporting security concerns
Security concerns and suspected vulnerabilities should be reported under the Vulnerability Disclosure Policy.
20. Contact
Security enquiries may be sent to info@terra-aqua.co.uk.
Version history
| Version | Date | Description |
|---|---|---|
| 1.0 | 21 July 2026 | Initial commercial release |