Skip to content
Tracbi

Security and trust

How we look after your account and data

Government contractors trust us with their pipeline. These are the controls in place today; our published security policy has the full detail.

Security architecture

Hosting

Serverless on Cloudflare

  • The application runs on Cloudflare Workers, with Cloudflare D1 for the database and R2 for attachments. We run no servers or virtual machines of our own.
  • The data-ingest service has no public address; the application reaches it over an internal Cloudflare binding.
  • Production deploys run only from our CI pipeline, after the automated checks pass.

Encryption and credentials

Encrypted, with no passwords to steal

  • TLS on every connection, including between the application and its providers.
  • Data at rest encrypted by the platform with AES-256-GCM.
  • No passwords: the product has none.
  • Session tokens are stored only as SHA-256 hashes.

Tenant isolation

One team can't see another's data

  • Every record a team owns carries that team's ID.
  • One data-access layer scopes every query to the signed-in session's team.
  • Another team's IDs are answered as “not found”.

Application hardening

Strict by default in the browser

  • A strict Content Security Policy: same-origin scripts, styles, fonts and images only, and no inline scripts or styles.
  • HTTP Strict Transport Security on every response.
  • Requests that change data are refused unless they come from our own pages.
  • Government attachments are treated as untrusted; PDFs open in a sandboxed viewer that can't run scripts.

Secure development

Every change reviewed and scanned

  • Changes are made only through pull requests.
  • Static analysis, a dependency audit and a secret scan run on every change.
  • Database queries use parameter binding.

Operations

Watched, recoverable and accountable

  • Automated health checks run daily on every source and the data pipeline, and the public status page shows how fresh each feed is.
  • The database can be restored to any minute in the last 30 days.
  • If an incident affects your data, we notify you within 72 hours of confirming it.
  • Staff access is limited to named people, and a support sign-in as one of your users is recorded in your team's audit log.

Identity and governance

Your identity provider, your policies, your audit trail

Single sign-on and directory sync

  • Connect Okta, Microsoft Entra ID, Google Workspace or any SAML or OIDC provider (Team and Enterprise).
  • Verify your email domain, so everyone at it signs in through your identity provider. With just-in-time provisioning, a colleague from a verified domain joins as a Viewer on first sign-in.
  • Sync users and groups with SCIM, and map directory groups to roles (Enterprise). Removing someone from the directory ends their access within minutes.

Sign-in policies

  • Require SSO: members must sign in through your identity provider.
  • Require MFA: members must sign in through SSO or with a passkey; an email code alone isn't enough.
  • Session limits: an idle timeout from 15 minutes to 24 hours, and a maximum session length from 1 hour to 30 days.
  • Lockout guard: an owner can turn a policy on only if their own session already meets it, so enabling it can't lock them out.
  • Policies are checked at sign-in and on every token refresh, so a change reaches open sessions within minutes.
Team roles
RoleWhat they can do
OwnerEverything an admin can do, plus billing.
AdminManages members, roles, sign-in settings, API keys and the audit log, and uses the product like a member.
MemberSearches, uses AI features, works on the pipeline, comments, manages alerts and runs exports.
ViewerRead-only access.

The audit log

  • Records security-relevant actions: invitations, role changes, removals, API keys, pipeline changes, exports, sign-in policy changes and staff support sign-ins.
  • Hash-chained: each event's SHA-256 hash covers the event before it, so owners and admins can check that past events haven't been changed.
  • Exportable as a CSV file, and streamable to your SIEM on Enterprise.

Offboarding

  • Suspend a member, sign them out of every session, or sign out the whole team at once.
  • With SCIM, removing someone from your directory removes them from the team.
  • An owner can download the team's data as a ZIP file at any time.

AI policy

  • Admins can turn AI on, limit it to admins, or turn it off, and can stop the team's profile being sent with AI requests.
  • Requests go only to providers that keep no copy and don't train on them. If none is available, the request fails rather than going elsewhere.
  • We never use your data to train models.

Compliance

Compliance status today

What we hold and what we don't, stated plainly.

Compliance status
AreaStatus today
SOC 2Not yet. We don't hold a SOC 2 report or other third-party certification. Cloudflare, WorkOS and Stripe hold their own, which cover their services, not ours.
FedRAMP, NIST SP 800-171, CMMCNot authorized or assessed. Tracbi is not built to hold Controlled Unclassified Information (CUI), and the Terms prohibit uploading it.
Data locationNot limited to one country. Data is stored on Cloudflare's network.
Vulnerability disclosurePublished, with a safe harbor for good-faith research. We acknowledge reports within 3 business days.

More detail