FAQ

Questions, answered.

Is this a compliance certification?

No. TerraSov gives you infrastructure that implements the technical controls and the evidence trail to prove it. Your auditor still audits — the difference is what they find: annotated code, an enforcing CI gate, and evidence guides mapping each control to its clause, instead of a spreadsheet someone updates the week before.

Which frameworks are covered?

ISO 27001:2022 (Annex A), BSI C5:2020, ENS (Spain, RD 311/2022), the GDPR articles with direct technical implications (Art. 32 security, Art. 44+ transfers), NIS2 (Directive 2022/2555, the Art. 21(2) measures every national transposition must contain) and DORA (Regulation 2022/2554, the ICT risk-management articles financial entities put in vendor questionnaires). 45 controls crosswalked across all six — one implementation, six vocabularies.

What exactly do I get access to?

A private GitHub repository with 26 Terraform modules — org foundation with EU region-lock SCPs, IAM and network baselines, KMS, audit logging, data stores (S3, RDS, Aurora, DynamoDB, OpenSearch, ElastiCache), containers and serverless (EKS, ECS, ECR, Lambda), API and edge, messaging, backup, vulnerability scanning and incident response — plus the custom Checkov policy pack, the terrasov-gate workflow, per-framework auditor evidence guides, and every future release while subscribed.

Can my whole company use it?

Yes — that's what you're buying. The license covers your legal entity, so anyone at your company can work with the code internally. What each plan caps is the number of engineer accounts: named GitHub accounts with direct read access to the repository (5 on Startup, 15 on Company).

How do engineer accounts work?

You assign them on the activate page — enter your checkout email plus a GitHub username, once per engineer. Replace a teammate by emailing support; need more accounts than your plan includes, just ask — we're not counting chairs.

What happens if I cancel?

Access stays active until the end of the paid period plus a 7-day grace window, then repository access is revoked automatically. Code you already deployed keeps working — modules you've applied don't stop existing. You lose updates, policies and new releases. Details in the Refund & Cancellation Policy.

Can I use the modules in client projects?

Infrastructure you deploy is yours — and your clients'. But if consulting is the business (your engineers using the library across client engagements, client repos running the gate), that's the Consultancy plan: email us and we'll put partner terms in writing. Redistributing the module source, the policy pack or the evidence guides as such is never allowed.

Why AWS only?

Because depth beats breadth for audits. The controls, SCPs and evidence commands are AWS-specific by design. If enough subscribers need another provider, that decision will be public on the roadmap.

Invoices and VAT?

Paddle is the merchant of record: it applies the correct VAT for your country (including reverse charge for EU businesses with a VAT ID) and issues invoices your accountant will accept without questions.

Do you offer trials?

The three open-source modules are the trial — same hardening, minus annotations, policies and evidence. And the public gate-demo repository shows the compliance gate blocking a real pull request, clause citations included. If they fit your workflow, the subscription adds the full compliance layer.