Security and trust
How we look after your account and data
Government contractors trust us with their pipeline. These are the controls in place today; our published security policy has the full detail.
Modern sign-in
Accounts sign in through WorkOS AuthKit with a one-time email code, a passkey, or your company's single sign-on. We never see or store a password.
Roles and sign-in policies
Everyone on your team is an Owner, Admin, Member or Viewer. Owners can require multi-factor sign-in for the whole team and, on plans that include them, single sign-on and directory sync (SCIM).
A team audit log
Owners and admins can view and export a log of security-relevant actions, such as invitations, role changes, API keys and exports. When our staff sign in as one of your members for support, that is in the log too.
Encrypted in transit and at rest
All traffic uses TLS. The application runs on Cloudflare, whose databases and object storage encrypt data at rest with AES-256-GCM.
Only the data we need
The solicitations we collect are public records. For your account we keep what sign-in and your team's settings need, as the privacy policy describes.
A strict browser policy
Our pages send a strict Content Security Policy. This site runs no JavaScript at all by default, loads no third-party trackers and hosts its own fonts.
Security architecture
Hosting
Serverless on Cloudflare
- The application runs on Cloudflare Workers, with Cloudflare D1 for the database and R2 for attachments. We run no servers or virtual machines of our own.
- The data-ingest service has no public address; the application reaches it over an internal Cloudflare binding.
- Production deploys run only from our CI pipeline, after the automated checks pass.
Encryption and credentials
Encrypted, with no passwords to steal
- TLS on every connection, including between the application and its providers.
- Data at rest encrypted by the platform with AES-256-GCM.
- No passwords: the product has none.
- Session tokens are stored only as SHA-256 hashes.
Tenant isolation
One team can't see another's data
- Every record a team owns carries that team's ID.
- One data-access layer scopes every query to the signed-in session's team.
- Another team's IDs are answered as “not found”.
Application hardening
Strict by default in the browser
- A strict Content Security Policy: same-origin scripts, styles, fonts and images only, and no inline scripts or styles.
- HTTP Strict Transport Security on every response.
- Requests that change data are refused unless they come from our own pages.
- Government attachments are treated as untrusted; PDFs open in a sandboxed viewer that can't run scripts.
Secure development
Every change reviewed and scanned
- Changes are made only through pull requests.
- Static analysis, a dependency audit and a secret scan run on every change.
- Database queries use parameter binding.
Operations
Watched, recoverable and accountable
- Automated health checks run daily on every source and the data pipeline, and the public status page shows how fresh each feed is.
- The database can be restored to any minute in the last 30 days.
- If an incident affects your data, we notify you within 72 hours of confirming it.
- Staff access is limited to named people, and a support sign-in as one of your users is recorded in your team's audit log.
Identity and governance
Your identity provider, your policies, your audit trail
Single sign-on and directory sync
- Connect Okta, Microsoft Entra ID, Google Workspace or any SAML or OIDC provider (Team and Enterprise).
- Verify your email domain, so everyone at it signs in through your identity provider. With just-in-time provisioning, a colleague from a verified domain joins as a Viewer on first sign-in.
- Sync users and groups with SCIM, and map directory groups to roles (Enterprise). Removing someone from the directory ends their access within minutes.
Sign-in policies
- Require SSO: members must sign in through your identity provider.
- Require MFA: members must sign in through SSO or with a passkey; an email code alone isn't enough.
- Session limits: an idle timeout from 15 minutes to 24 hours, and a maximum session length from 1 hour to 30 days.
- Lockout guard: an owner can turn a policy on only if their own session already meets it, so enabling it can't lock them out.
- Policies are checked at sign-in and on every token refresh, so a change reaches open sessions within minutes.
| Role | What they can do |
|---|---|
| Owner | Everything an admin can do, plus billing. |
| Admin | Manages members, roles, sign-in settings, API keys and the audit log, and uses the product like a member. |
| Member | Searches, uses AI features, works on the pipeline, comments, manages alerts and runs exports. |
| Viewer | Read-only access. |
The audit log
- Records security-relevant actions: invitations, role changes, removals, API keys, pipeline changes, exports, sign-in policy changes and staff support sign-ins.
- Hash-chained: each event's SHA-256 hash covers the event before it, so owners and admins can check that past events haven't been changed.
- Exportable as a CSV file, and streamable to your SIEM on Enterprise.
Offboarding
- Suspend a member, sign them out of every session, or sign out the whole team at once.
- With SCIM, removing someone from your directory removes them from the team.
- An owner can download the team's data as a ZIP file at any time.
AI policy
- Admins can turn AI on, limit it to admins, or turn it off, and can stop the team's profile being sent with AI requests.
- Requests go only to providers that keep no copy and don't train on them. If none is available, the request fails rather than going elsewhere.
- We never use your data to train models.
Compliance
Compliance status today
What we hold and what we don't, stated plainly.
| Area | Status today |
|---|---|
| SOC 2 | Not yet. We don't hold a SOC 2 report or other third-party certification. Cloudflare, WorkOS and Stripe hold their own, which cover their services, not ours. |
| FedRAMP, NIST SP 800-171, CMMC | Not authorized or assessed. Tracbi is not built to hold Controlled Unclassified Information (CUI), and the Terms prohibit uploading it. |
| Data location | Not limited to one country. Data is stored on Cloudflare's network. |
| Vulnerability disclosure | Published, with a safe harbor for good-faith research. We acknowledge reports within 3 business days. |