Security at ServiQ

Last updated October 2026

ServiQ is built by TerraSecure to hold the kind of data service teams can't afford to lose control of — ticket content, asset records, and, in the password vault, credentials. This page describes the technical and architectural controls built into the product. It isn't a substitute for your own organization's risk assessment, and we're glad to answer specific questions at security@terrasecure.co.

Tenant isolation

ServiQ is multi-tenant: every record — tickets, assets, knowledge articles, vault entries, audit logs — is scoped to the organization that created it, and every query the application makes is filtered by that organization's identifier. There is no cross-tenant query path in normal use.

TerraSecure support staff do not have standing access to customer data. When a platform administrator needs to assist an organization, they explicitly enter a time-limited, reason-logged “organization view” session — visible in that organization's own audit log — rather than impersonating a user or querying data silently.

Encryption

Data in transit is encrypted with TLS. User account passwords are hashed with bcrypt, a one-way hash — ServiQ never stores a recoverable copy of a login password. Sensitive secrets that the application does need to recover on your behalf — MFA provisioning secrets, SAML certificates, and password vault entries — are encrypted at rest with AES-256-GCM, authenticated encryption with a unique random value per secret.

Password vault

The password vault is off by default and enabled per person by a tenant administrator. Vault entries are encrypted as described above; administrators can grant or revoke access to the feature, but cannot read vault contents themselves — not through the product, and not through an organization-view session, which explicitly excludes the vault.

A few things the vault does on its own:

  • Generates passwords meeting CISA's published complexity guidance (16+ characters, mixed case, digits, and symbols) using a cryptographically secure random source.
  • Checks new and saved passwords against Have I Been Pwned's Pwned Passwords database using k-anonymity — only a 5-character fragment of a cryptographic hash ever leaves the server, never the password or its full hash.
  • Reminds the owner to rotate a password after 90 days, and emails the owner whenever someone they've shared a secret with actually reveals it.

Authentication & sessions

ServiQ supports optional TOTP multi-factor authentication for any account, and SAML single sign-on for Enterprise organizations. Sessions are a signed, httpOnly, secure cookie — never readable by page scripts — and are revalidated against the database on every request, so suspending a user or disabling their access takes effect immediately rather than at next login.

Access control

Access is layered: a tenant role (requester, agent, manager, administrator, and a few specialized roles) controls what a person can do; queue membership controls which departmental tickets they can see, including queues an administrator has marked restricted; and a per-user feature toggle controls whether someone can reach service tickets, the asset inventory, or the password vault at all. A separate, orthogonal platform role exists only for TerraSecure's own staff and never grants tenant-role permissions inside a customer organization.

Audit logging

Account changes, permission changes, sharing and reveal events in the password vault, and platform-staff organization-view sessions are all written to an append-only audit log, scoped to and visible within your organization.

Infrastructure

ServiQ runs on Railway with a managed PostgreSQL database. Application and database infrastructure are kept current with platform security updates as part of normal operation.

Reporting a vulnerability

If you believe you've found a security issue in ServiQ, please email security@terrasecure.co with enough detail to reproduce it. We ask that you give us a reasonable opportunity to investigate and address a report before any public disclosure, and we won't pursue legal action against good-faith research conducted under that understanding.