What Security Certifications Does Teller Have?
Teller maintains SOC 2 Type 2 certification and PCI DSS compliance, with infrastructure hosted on AWS with geographic redundancy. Security isn't an add-on — it's foundational to how our platform is built and operated.
SOC 2 Type 2 Certified
Teller undergoes annual SOC 2 Type 2 audits conducted by independent third-party auditors. This certification validates that our security controls are not only designed correctly but operating effectively over time.
The audit covers:
- Security policies and procedures
- Access controls and authentication
- Data encryption and protection
- Incident response and monitoring
- Change management processes
Current SOC 2 reports are available to existing and prospective clients under NDA. Please reach out to us directly if you'd like to review these reports.
PCI DSS Compliance
Teller uses a semi-integrated payment architecture that keeps cardholder data out of the core application. When a customer swipes, dips, or taps their card:
- Card data goes directly to the payment processor
- Teller receives only a token and authorization response
- No card numbers are stored, processed, or transmitted through Teller
This approach dramatically reduces PCI scope for your agency while maintaining full payment functionality.
Infrastructure Security
Teller runs on Amazon Web Services (AWS) with:
- Primary data center: AWS US-West (Oregon)
- Disaster recovery: AWS US-East (Virginia)
- Data replication: Multi-AZ with continuous replication
- Recovery objectives: RPO of 5 minutes, RTO of 1 business day
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
Access Controls
Teller supports enterprise authentication:
- Single Sign-On (SSO) via OpenID Connect
- Azure Active Directory integration
- ADFS compatibility
- Role-based permissions with granular controls
Your IT team maintains control over who can access what, with full audit logging of all user activity.
Learn More
Need security documentation for your procurement process? Contact us to request our security package.