telos
ProductWho it's forOutcomes
Book a demo
Legal

Data & Security

Last updated: July 27, 2026

Telos handles sensitive financial data for every business you serve. This is how we protect it, who can access it, and the control you keep over it.

Our approach

Institutions trust Telos with a live view of their clients' cash, runway, revenue, and risk. That only works if the underlying data is protected at every step. Security and privacy are built into how the platform is designed, not added on afterward, and we hold ourselves to the standards our customers are accountable to.

Encryption

All data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256. Connections to your clients' accounting, banking, and payments providers are made over encrypted channels using scoped, revocable credentials rather than stored passwords wherever the provider supports it.

Tenant isolation

Every organization's data is logically isolated so that one institution can never see another's portfolio. Within your organization, each client business is scoped so that access can be granted and revoked per engagement. Disconnecting a client immediately stops further data collection for that business.

Access controls

  • Role-based access so team members only see the clients and functions they are assigned.
  • Single sign-on and multi-factor authentication supported for account access.
  • Internal access to Customer Data is restricted to the minimum personnel needed to operate and support the service, logged, and reviewed.
  • Production access requires strong authentication and is granted on a least-privilege basis.

How we use your data

We use Customer Data only to operate the platform for you: consolidating financial signals, surfacing what needs attention, and recommending next actions. We never sell your data and we do not share it with third parties for advertising. Any aggregated insights we produce are de-identified and cannot be traced back to a specific institution or business.

Subprocessors

We rely on a small set of vetted infrastructure and data-connectivity providers to deliver the service. Each is held to contractual data-protection obligations consistent with these commitments. We maintain a current list of subprocessors and provide advance notice of material changes on request.

Data retention and deletion

We retain Customer Data for as long as your account is active or as needed to provide the service. When you disconnect a client or close your account, we make the associated data available for export for a limited period and then delete it from active systems, with backups aging out on a defined schedule. You can request deletion at any time by contacting us.

Monitoring and incident response

We continuously monitor our infrastructure for anomalous activity and maintain an incident response process. In the event of a security incident affecting your data, we will notify affected customers without undue delay and provide the information needed to meet your own obligations.

Your responsibilities

Security is shared. You are responsible for maintaining the authorization to access each client business you connect, for managing your team's access and offboarding promptly, and for protecting the credentials used to sign in to Telos.

Contact

To report a vulnerability, request our subprocessor list, or ask about our security practices, contact hello@gettelos.com.

© 2026 Telos. All rights reserved.
Terms of ServiceData & Security