Customer portal System status Developers Contact Search
Contact

Security contact

Reporting a vulnerability, an abuse issue or a suspected phishing campaign.

security@terravek.com

For security vulnerabilities in any Terravek product, service or website. We acknowledge within 72 hours, provide an assessment within ten working days, and keep you informed until it is resolved.

You do not need to sign anything before reporting, and we will not ask you to. Full disclosure policy · /.well-known/security.txt

Other security addresses

AddressUse for
security@terravek.comVulnerability reports, security questions, coordinated disclosure
abuse@terravek.com", Abuse of Terravek services or infrastructure, including suspected misuse by a customer
soc@terravek.comSecurity Operations Centre — for existing customers with an active incident
postmaster@terravek.comMail delivery, SPF, DKIM and DMARC issues
hostmaster@terravek.comDNS and domain administration

Suspected phishing

If you have received something that appears to come from Terravek and you are not sure, forward it to security@terravek.com with full headers if you can. We would far rather see a hundred false alarms than miss one campaign, and you will get a reply from a person.

Things Terravek will never do:

  • Ask for your password or a multi-factor code, by any channel
  • E-mail a link asking you to "revalidate" or "reconfirm" portal credentials
  • Change our bank details by e-mail. Our bank details do not change.
  • Ask a supplier to redirect payment to a new account

The only legitimate sign-in domains are portal.terravek.com, partners.terravek.com and identity.terravek.com.

Who you will hear from

Reports are triaged by Laura Peeters (Security Engineer, Application Security) and escalated as needed to Riina Tamm (Head of Security Operations) and Ingrid Halvorsen (Chief Information Security Officer). Responses are written by an engineer, not by a lawyer, which is deliberate.

Coordinated vulnerability disclosure policy · Last year's disclosure statistics