Security
How Traack protects the evidence you trust it with.
Last updated 7 September 2026
Our approach
Audit evidence is sensitive by definition. It names people, shows how money moves and records where controls failed. Traack is built so that your team can answer your own auditors' questions about where that evidence went, who touched it and what was done with it.
This page describes the controls we operate today. Customers under NDA can request our SOC 2 Type II report, penetration test summaries and subprocessor list from their account contact.
Data protection
- Encrypted in transit with TLS 1.2 or later and at rest with AES-256, including uploaded files, sandbox contents, database records and backups.
- Each person works in an isolated workspace with its own sandbox and file storage. Evidence never crosses between people, teams or client organisations.
- Production infrastructure runs on SOC 2 and ISO 27001 certified cloud providers. We hold no physical infrastructure.
- Secrets and integration credentials are stored in a managed secrets store, never in code, logs or the sandbox.
Access control
- Sign in through Google or a one-time email code. Traack never stores passwords. Single sign-on through your identity provider is available for organisations.
- Access to production systems by Traack staff requires hardware-backed multi-factor authentication and is limited to the people who operate the service.
- Every administrative action on your account, and every action the agent takes, is written to an audit log you can review and export.
How the agent behaves
- The agent reads by default. Any action that would send, change or delete in a connected system stops and asks for your approval first, and the audit log records who agreed.
- Every command the agent runs, every query it makes and every raw response it receives is recorded and replayable, so an external auditor can see exactly what was done, on which records and when.
- Integrations use scoped OAuth grants. You can revoke any integration at any time from the app or from the source system.
Data retention
- Your evidence is processed for your engagement and nothing else. It is never used to train any model, ours or a third party's.
- Model providers we use operate under zero data retention agreements. Prompts and responses are not stored by the provider after the request completes.
- You control retention. Files and threads are deleted when you delete them, and your whole workspace is deleted within 30 days of a written request or the end of your contract.
Incident response
We monitor the service continuously and run an incident response process with defined severity levels. If an incident affects your data we will notify your account contact without undue delay, and in any case within 72 hours of confirming it, with what happened, what was affected and what we are doing about it.
Reporting a vulnerability
If you believe you have found a vulnerability in Traack, email security@traack.ai. We acknowledge reports within two business days and will not take legal action against good-faith research that respects our customers' data. Please do not access data that is not yours and do not run automated scanners against production.