Ternivo Security
Access controls
- Authenticated accounts are required for private trip data.
- Database row-level security is used to separate user and shared-trip access.
- Server-only credentials are kept out of public clients.
- Trip-sharing permissions are scoped to the role granted by the trip owner.
Data in transit and storage
Ternivo uses encrypted HTTPS connections for network traffic. Production data and uploaded content are hosted with established cloud service providers and protected by authenticated access controls and provider security features.
Reservation forwarding
Travel confirmations forwarded to a user's private Ternivo trip address are processed to extract the travel information needed to organize the trip. Ternivo V1 does not require broad read access to a user's email mailbox.
AI processing
When an AI feature is used, only the context needed for that feature should be sent to the relevant AI service. Ternivo's product design favors structured, scoped requests rather than unrestricted access to a user's account data.
Offline travel data
Critical trip information may be cached on a user's device for offline use. Ternivo's release architecture scopes offline data to the authenticated user and is designed to purge private cached data during sign-out or account switching.
Responsible reporting
If you believe you have found a security issue involving Ternivo, contact security@ternivo.app. Please do not publicly disclose an issue before we have had a reasonable opportunity to investigate it.
Privacy
For additional details about information handling, see the Ternivo Privacy Policy or contact privacy@ternivo.app.