Skip to main content
Tess operates cloud-first: physical data-center controls belong to the cloud provider; Tess designs and operates the logical layer — networks, cloud identity, encryption, backups, and protection of internet-facing surfaces.

Production environment

  • Production workloads run in segregated networks, separated from non-production use.
  • Ingress traffic goes through load balancing and service health checks.
  • Network rules restrict which systems can communicate — especially administrative paths.
  • Privileged infrastructure access is limited to authorized people and is logged.

Edge and public surfaces

  • DNS, content distribution, and edge protections help absorb abuse and volumetric attacks.
  • Edge filtering reduces malicious traffic before it reaches the application.
  • Sensitive public endpoints require encrypted communication.
  • Physical controls (facility, power, hardware access) are the cloud provider’s responsibility, monitored by Tess through reports and contractual obligations.

What this means for the customer

You do not need to operate Tess servers. Isolation between customers, encryption, and perimeter protection are part of the service. Your responsibility remains networks, devices, and identities in your own company when accessing the platform.
In audits, Tess describes and evidences the controls under its management and monitors the security assurances published by critical providers (cloud shared-responsibility model).