Security
Your conversations stay yours
Tern holds some of the most sensitive material a sales team has: what customers said, in their own words. Here is how we keep it isolated, encrypted and accountable.
Tenancy isolation
Every record in Tern belongs to exactly one organisation. The organisation id is part of every table, every query and every background job. Every API request is resolved to a single workspace before any data is read.
Row level security
Isolation is enforced by the database, not only by application code. Row level security policies filter every read and write to the current organisation, so a bug in a query cannot leak another customer's data.
Encryption at rest and in transit
Databases, file storage and backups are encrypted at rest. Every connection between your browser, the extension, the application and its services uses TLS. Sign in is passwordless with expiring links, so there are no passwords to steal.
Signed asset links
Recordings, transcripts and media are never on a public address. Each playback or download uses a short lived signed link issued only to a signed in user of the right workspace. It expires within minutes.
Audit trail
Every view of a recording, every change to a lead and every settings change is written to an append only audit trail with who, what and when. Administrators can review it in the application and export it.
Access for our staff
Our staff have no standing access to customer data. Support access is granted per incident and time limited. It lands in the same audit trail you can see.
Tern Bridge
How the bridge works
The Tern Bridge is a browser extension that turns the tabs your agents already have open into capture sources. It is designed around one rule: it never acts for a person who is not there.
Capture
On a connected site such as WhatsApp Web, Messenger, Instagram, LinkedIn, Gmail or Outlook, the extension watches the open thread and, when it changes, reads the visible messages and sends them to your workspace. It uses the agent's own signed in session and only runs on the sites you have connected. If no tab is open, nothing is captured. A click to log button saves a thread by hand when needed.
Assisted send
When Tern drafts a reply, the draft appears in the extension's side panel with the lead's context. If the agent chooses it, the extension places the text in the site's own composer and stops. The agent reads it and presses the site's own send button. The extension never presses send.
The hard boundary
- No typing, clicking or navigating for a human who is not present.
- No headless or cloud browsers, no session sharing, no anti detection techniques.
- A per site limit on how many drafts are surfaced per day, spaced out and inside the lead's business hours, so a person is never handed a bulk queue.
- Fully automatic sending is only available on official platform interfaces, never through the bridge.
Keeping it safe
- The extension talks only to your workspace, with a token that is scoped to one user and expires.
- The rules that describe how to read each site are signed and versioned. A site whose rules are missing or fail verification stops capturing rather than guessing.
- An administrator can pause capture or sending for any single site from settings without uninstalling anything.
- Call audio from a connected site is recorded only when your recording policy is on and the agent has confirmed the consent announcement.
Where data lives
Customer data is stored in Australia and Singapore. Recordings and media stay in Australia. Details are in the privacy policy.
AI processing is a switch
One organisation level setting decides whether any conversation is sent to an AI model. Off means off: capture continues and rules score leads instead.
Report a concern
Found something? Write to support@ternup.io for security reports and privacy@ternup.io for privacy questions. We acknowledge within one business day.