Your dev team ships code 50x a day. Your security reviews happen in Excel. See the problem? Embed security reviews directly into your development workflow to mitigate risks before the first line of code is written. #AppSec #SecurityAutomation
TerraTrue
Software Development
San Francisco, California 4,112 followers
For champions of trust.
About us
TerraTrue empowers teams to build privacy and security into everything they do through a collaborative, intuitive, and scalable platform. Purpose-built to work with modern product development, TerraTrue seamlessly captures structured data about how teams plan to collect, use, store, and share data. The platform then maps that digital blueprint to the world’s privacy laws to automate guidance, risk-flagging, and downstream data maps and reports. Sitting as a hub between product teams and review teams, TerraTrue also smartly routes rule-based workflows throughout an organization, automatically detects and reports infrastructure changes in cloud environments, and drives vendor management — all from the same single source of truth. Using TerraTrue, companies run a scalable, fast privacy-by-design program that eliminates spreadsheets, manual ad-hoc processes, and compliance bottlenecks. TerraTrue was founded in 2018 by former Snapchat execs. Modern brands like Lyft, Robinhood, Roku, and Foursquare are shifting left to get privacy right with TerraTrue.
- Website
-
http://terratrue.com
External link for TerraTrue
- Industry
- Software Development
- Company size
- 51-200 employees
- Headquarters
- San Francisco, California
- Type
- Privately Held
- Founded
- 2018
- Specialties
- privacy by design, data privacy, privacy compliance, data privacy management, privacy reviews, DPIA and LIA Reporting, CCPA and GDPR Compliance, Data Privacy Reporting, Data Mapping, Data Visualization, privacy technology, VCDPA, and data mapping
Products
TerraTrue
Data Privacy Management Software
TerraTrue empowers teams to build privacy and security into everything they do through a collaborative, intuitive, and scalable platform. Purpose-built to work with modern product development, TerraTrue seamlessly captures structured data about how teams plan to collect, use, store, and share data. The platform then maps that digital blueprint to the world’s privacy laws to automate guidance, risk-flagging, and downstream data maps and reports. Sitting as a hub between product teams and review teams, TerraTrue also smartly routes rule-based workflows throughout an organization, automatically detects and reports infrastructure changes in cloud environments, and drives vendor management — all from the same single source of truth. With TerraTrue’s digital privacy platform, companies run a scalable, fast privacy-by-design program that eliminates spreadsheets, manual ad-hoc processes, and compliance bottlenecks.
Locations
-
Primary
San Francisco, California 94105, US
Employees at TerraTrue
Updates
-
Looking to adopt more AI solutions into your business next year? What kind of risks are you introducing? What's the plan to mitigate those risks? At 12pm EST/9am PST today, learn about the latest trends to proactively manage privacy, security, and AI risks for 2025. #securitybydesign #privacybydesign #aigovernance https://lnkd.in/gVr8cbQb
-
TerraTrue reposted this
Take Control of Your Security: Automated Authentication with TerraTrue We’re thrilled to announce a new functionality to our platform: fully automated authentication. What does this mean for you? ➡️ Effortless SSO Setup: Configure Single Sign-On (SSO) with your identity provider in just a few clicks. No more back-and-forth with our team to load your certificate and related information. ➡️ Flexible Authentication Options: Tailor your authentication settings to your specific needs. Enable or disable SSO, make it mandatory or optional, add additional authentication mechanisms, adjust session duration, and monitor user login activity. ➡️ Seamless Certificate Management: Upload multiple SSO certificates to ensure a smooth transition when one expires. Rest easy, TerraTrue will proactively notify you about expiring certificates. A Team Effort We’re grateful to our talented team, especially Security Engineer Felipe Santiago and Designer Joyce Lee, for all their hard work in bringing this feature to life. With this latest enhancement, we continue to empower our customers with greater control and security.
-
Join us tomorrow to discuss the latest trends in: 🔥 Security by-design 🔥 Third party risk management 🔥 AI risk mitigation https://lnkd.in/gVr8cbQb #securitybydesign #ai #cybersecurity
Trends in Privacy & Security by Design · Zoom · Luma
lu.ma
-
Join us next week for an info packed session with expert insights on the trends in privacy and security by design! We'll cover: 🚩 Artificial intelligence 🚩 Organizational efficiency 🚩 Data mapping 🚩 Third-party risk management 🚩 Regulatory complexity https://lnkd.in/gVr8cbQb Speakers Jad Boutros Cofounder & CEO at TerraTrue Former Chief Security Officer at Snap Anthony Prestia VP Privacy at TerraTrue Former Senior Privacy Counsel at Snap Get practical strategies to stay ahead of emerging challenges. #privacybydesign #securitybydesign
Trends in Privacy & Security by Design · Zoom · Luma
lu.ma
-
How many privacy legal reviews could you anticipate doing? Whether you're starting a privacy and security by-design program, or whether you are simply interested in data points to help you assess the health of your established program, you may find our new series of posts to be helpful. In this first post, we look at the number of privacy legal reviews our customers are conducting. Why is this an important metric? ➡️ It helps you set realistic expectations for yourself. Take on too many reviews and you're more likely to become overwhelmed. Not only will you be unhappy, you'll also add delays downstream with your developers and your other internal customers, impacting the speed of execution on the business. Unhappiness is contagious 😄. ➡️ It helps you structure your privacy-by-design program. A successful privacy program aims to maximize visibility on what the business is doing, and yet effectively prioritize which reviews to conduct in order to stay above water. Unsurprisingly, our data shows that we generally have two sets of privacy reviewers: (a) a core set of reviewers such as privacy counsels who are shouldering the bulk of the privacy reviews in their organization, and (b) additional reviewers – often in leadership roles – who may step-in on specialized reviews or when the team is overloaded. We looked at data over the past year, analyzing the number of privacy legal reviews completed by reviewers who have been in their role for the full year. We ignored the occasional reviewer who has conducted less than 10 reviews in the past year. Under those parameters, we find that a privacy reviewer is performing on average 68 privacy legal reviews annually across our customer base, with a fairly large standard deviation of 95. Typically, when a reviewer is tackling third-party privacy reviews as opposed to internal product privacy reviews, they tend to do more. Food for thought: ✅ Aim to gain as much visibility on what the business is doing, in order to reduce blindspots. ✅ Prioritize the incoming reviews based on risk to demonstrate the highest impact. Take into account how many reviews you are able to conduct. Automate that prioritization if your review platform supports it. ✅ Consider quickly closing the reviews you won't be able to get to, to avoid delaying the business unnecessarily. Automate that action if your review platform supports it. If there are any metrics you'd like to see, let us know. 🙌
-
How will your privacy and security teams handle AI risk in 2025? Next week Jad Boutros (CEO) and Anthony Prestia (VP of Privacy ) will be discussing trends and solutions to address some of these risks. Topic areas include: ✅ How privacy teams are being tasked with overall AI risk governance ✅ Risks related to personal data – both internal and acquired data – being used for training under certain laws ✅ Risk that implementation of AI can be used to make discriminatory decisions (similar to prohibits under GDPR and state privacy laws) ✅ Risks that employees may leak confidential or proprietary information because they don’t understand how these tools work And more. #privacybydesign #securitybydesign #iapp Sign up below. 👇 https://lnkd.in/gVr8cbQb
Trends in Privacy & Security by Design · Zoom · Luma
lu.ma
-
How Ancestry Scaled Privacy Reviews From Hours to Minutes "Trust is actually one of our top pillars here at Ancestry," Stalder told TerraTrue. "Without that, we're not going to have many customers relying on us for their service." #privacybydesign #securitybydesign https://lnkd.in/gyn2FhnP
How Ancestry Scaled Privacy Reviews From Hours to Minutes | TerraTrue
terratruehq.com
-
Save the date for Wednesday December 11th to get more insights from Jad on the future of privacy and security. https://lnkd.in/gVr8cbQb
Why conduct security and privacy reviews? "Because it is the right thing to do," would have answered my younger self with an idealistic and passionate spirit encouraged by working at companies that take security and privacy seriously. After all, we choose to work in this field because we care about protecting our users and our company, don't we? As we progress in our career and take increasing responsibility for people and programs, it becomes harder to ignore the economic reality that talent and budgets are finite, even more so in this current macro-environment. So here are a few key ways you can assign a value to a strong privacy and security review function to help yourself and others justify the costs involved (or make appropriate changes). 💢 It improves the top-line of the business by enabling product and engineering (and the rest of the business) to execute faster. Studies indicate that a strong security and privacy by-design program can speed up development by 10-20% overall, which is incredibly significant. This is because privacy and security bugs are found earlier in the SDLC, can be remedied at lower cost, and introduce fewer delays and fewer patches. Also, strong reviews lead to a better product architecture and resiliency, resulting in an improved user experience. Lastly, for B2B companies, it is tablestake in order to get the SOC-2 you need to win deals. 💢 It improves the bottom-line of the business by lowering the number of and impact of security and privacy breaches (often costing in the millions of 💰), and reduces the time needed to conduct incident response. Also, organizations conducting risk assessments are more likely to comply with industry regulations (like GDPR, HIPAA, etc.), which helps avoid fines and reputational damage. 💢 For privacy and security teams specifically, conducting regular reviews and identifying risks early, can save on spending towards unnecessary security and privacy defenses and result in a more efficient resource allocation which can save a good % of your budget. This is worth considering as you assess your budget every year and look for waste. The list above is by no means exhaustive. There are also benefits of increasing competitive advantage and user trust, building a better risk-based legal strategy, and expediting compliance audits, among others. Your privacy and security reviews keep users safe which is key but they impact the business in other ways too, so keep them up! Comment if you have some thoughts!
-
TerraTrue reposted this
Why conduct security and privacy reviews? "Because it is the right thing to do," would have answered my younger self with an idealistic and passionate spirit encouraged by working at companies that take security and privacy seriously. After all, we choose to work in this field because we care about protecting our users and our company, don't we? As we progress in our career and take increasing responsibility for people and programs, it becomes harder to ignore the economic reality that talent and budgets are finite, even more so in this current macro-environment. So here are a few key ways you can assign a value to a strong privacy and security review function to help yourself and others justify the costs involved (or make appropriate changes). 💢 It improves the top-line of the business by enabling product and engineering (and the rest of the business) to execute faster. Studies indicate that a strong security and privacy by-design program can speed up development by 10-20% overall, which is incredibly significant. This is because privacy and security bugs are found earlier in the SDLC, can be remedied at lower cost, and introduce fewer delays and fewer patches. Also, strong reviews lead to a better product architecture and resiliency, resulting in an improved user experience. Lastly, for B2B companies, it is tablestake in order to get the SOC-2 you need to win deals. 💢 It improves the bottom-line of the business by lowering the number of and impact of security and privacy breaches (often costing in the millions of 💰), and reduces the time needed to conduct incident response. Also, organizations conducting risk assessments are more likely to comply with industry regulations (like GDPR, HIPAA, etc.), which helps avoid fines and reputational damage. 💢 For privacy and security teams specifically, conducting regular reviews and identifying risks early, can save on spending towards unnecessary security and privacy defenses and result in a more efficient resource allocation which can save a good % of your budget. This is worth considering as you assess your budget every year and look for waste. The list above is by no means exhaustive. There are also benefits of increasing competitive advantage and user trust, building a better risk-based legal strategy, and expediting compliance audits, among others. Your privacy and security reviews keep users safe which is key but they impact the business in other ways too, so keep them up! Comment if you have some thoughts!