Third Party Index

Snapshot 13438

Document
Subprocessor list
URL
https://security.tesorio.com/?itemUid=e3fae2ca-94a9-416b-b577-5c90e382df57
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
377423 bytes
SHA-256 (raw)
720e3a4ebaf88877ab6bd3ff3336ad57c0e6567395606468b115c744febdabc6
SHA-256 (normalized text)
6c1d4073b63facb2da67895eea3dd2c26dcd443a89a384fdecf78b8f98e4759c

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Subprocessor Updates
Security Portal
Start your security review
View & download sensitive information
Ask for information
Overview
Tesorio has implemented best-in-class security practices to keep customer data safe
More than just collections management and accounts receivable automation, Tesorio is the world’s first and only cash flow performance platform. Tesorio empowers CFOs and finance teams to boost profits by using artificial intelligence to better manage, predict, and collect cash.
Compliance
CCPA
GDPR
PCI DSS
SOC 1
SOC 2
Tesorio is reviewed and trusted by
Veeva Systems
Couchbase
Highspot
Smartsheet
Domo
Coupa Software
Documents
Featured Documents
REPORTSPentest Report
REPORTSSOC 1 Report
REPORTSSOC 2 Report
POLICIESComplete Policy Packet
Risk Profile
Data Access LevelRestricted
Impact LevelSubstantial
Recovery Time Objective24 hours
View more
Product Security
Audit Logging
Data Security
Integrations
View more
Reports
Pentest Report
SOC 1 Report
SOC 2 Report
Self-Assessments
CAIQ
SIG Lite
Data Security
Access Monitoring
Data Backups
Data Erasure
View more
App Security
Responsible Disclosure
Code Analysis
Credential Management
View more
AI (Artificial Intelligence)
EU AI Act Compliance
Artificial Intelligence Policy
Legal
Subprocessors
Cyber Insurance
Data Processing Agreement
View more
Access Control
Data Access
Logging
Password Security
Infrastructure
Amazon Web Services
Anti-DDoS
Infrastructure Security
View more
Endpoint Security
Endpoint Detection & Response
Network Security
Firewall
IDS/IPS
Spoofing Protection
View more
Corporate Security
Asset Management Practices
Email Protection
Employee Training
View more
Policies
Complete Policy Packet
Security Portal Updates
Subprocessor Updates
Subprocessors
Tesorio has added Deepgram, Inc. to its list of subprocessors.
Purpose: Automatic Speech Recognition (ASR) platform that provides transcription services for audio content.
Location: USA.
Tesorio has added Unified API, Inc. to its list of subprocessors.
Purpose: Video Conferencing / Communications API Aggregator.
Location: USA.
Tesorio has added Anthropic, PBC to its list of subprocessors.
Purpose: AI / Large Language Model Provider.
Location: USA.
For AI subprocessors, any data processing is subject to Tesorio's AI policies. You can review our AI commitments and practices here.
Tesorio has added Adyen N.V. to its list of subprocessors.
Purpose: Payment Processing.
Location: USA, EU.
Tesorio has added Browserbase, Inc. to its list of subprocessors.
Purpose: Headless Web Browser.
Location: USA.
Tesorio has added Basepilot, Inc. to its list of subprocessors.
Purpose: AI Browser Automation.
Location: USA.
Tesorio has added Astronomer, Inc. to its list of subprocessors.
Purpose: Managed Apache Airflow Services.
Location: USA.
Tesorio has added CrowdView, Inc. dba Extend to its list of subprocessors. Purpose: Document Data Extraction & Processing. Location: USA.
Tesorio has added OpenAI, L.P. to its list of subprocessors. Purpose: ML/AI Data Processing. Location: USA.
Tesorio has now moved to manage subprocessor listings to our security portal. You can view our list of subprocessors here. All updates will now be recorded here on our security portal. Before this change, the last time subprocessors were updated were on February 12, 2022. If you would like to receive email notifications around subprocessor updates, please click the "Subscribe" button and submit your email.
SOC Report Updates
Compliance
We have just uploaded our SOC 1 Type 2 and SOC 2 Type 2 reports covering the period from March 1, 2025 - February 28, 2026
We have just uploaded our SOC 1 Type 2 and SOC 2 Type 2 reports covering the period from March 1, 2024 - February 28, 2025
We have just uploaded our SOC 1 Type 2 and SOC 2 Type 2 reports covering the period from March 1, 2023 - February 29, 2024
We have just uploaded our SOC 1 Type 2 and SOC 2 Type 2 reports covering the period from March 1, 2022 - February 28, 2023
Tesorio Update on 2022 OpenSSL 3 Vulnerabilities
Vulnerabilities
Tesorio has become aware of the recently announced OpenSSL vulnerabilities CVE-2022-3786 and CVE-2022-3602. After a review, we have concluded that there is no impact to Tesorio or its customers at this time. Our cloud infrastructure partner provided a patch to our systems on November 1, 2022.
Tesorio will continue to monitor the situation closely and will provide updates where we have them available to us.
Sincerely,
Fabio Fleitas
Chief Technology Officer
Tesorio Update on Heroku/GitHub
Incidents
Last Friday, Tesorio became aware of an incident that occurred with Heroku & GitHub. Tesorio conducted an internal investigation with the recommendations from Heroku & GitHub and have determined that we were not impacted by this issue.
Tesorio will continue to monitor the situation closely and will provide updates where we have them available to us.
Tesorio values the security of its services extremely highly and to this end we maintain appropriate industry accepted third party accreditation of our security controls and program.
Sincerely,
Fabio Fleitas
Chief Technology Officer
Tesorio Update on SpringShell
Vulnerabilities
Tesorio became aware of a recently disclosed CVE-2022-22965 - "SpringShell" RCE vulnerability in spring-beans before 5.2.20/5.3.18, Tesorio can confirm we have conducted an internal investigation and can confirm that we have no evidence that Tesorio customers or internal employees have been targeted or impacted by this vulnerability.
Tesorio will continue to monitor the situation closely and will provide updates where we have them available to us.
Tesorio values the security of its services extremely highly and to this end we maintain appropriate industry accepted third party accreditation of our security controls and program.
Sincerely,
Fabio Fleitas
Chief Technology Officer
If you think you may have discovered a vulnerability, please send us a note.
Report issue