Security | Trakkr
Security at Trakkr.
Enterprise-grade infrastructure. Industry-standard encryption. Your data is protected so you can focus on your brand.
Your data is protected by industry leaders.
Infrastructure
Supabase
PostgreSQL database with row-level security
- SOC 2 Type II
- HIPAA
Google Cloud
Cloud Run serverless containers
- SOC 2
- ISO 27001
- GDPR
Cloudflare
Global CDN and DDoS protection
- SOC 2
- ISO 27001
- PCI DSS
All vendors SOC 2 certified
Data encrypted in transit and at rest
How we protect your data.
- Encryption in transit: TLS 1.3
- All data encrypted between your browser and our servers
- Encryption at rest: AES-256
- Database and backups encrypted using industry-standard encryption
- Data isolation: Row-Level Security
- Each customer's data is isolated at the database level
- Access control: Role-based (RBAC)
- Fine-grained permissions for team members and clients
- Authentication: MFA available
- Two-factor authentication for enhanced account security
- Secure sessions: JWT + HTTP-only
- Secure session management with automatic expiration
Privacy-first by design.
- Minimal data collection - only what's necessary
- GDPR-compliant data handling practices
- Data processed in secure, certified regions
- No data sold to third parties - ever
- Data export available on request
- Data deletion within 30 days on request
- Transparent sub-processor list
- Privacy policy regularly updated
- Full details in our privacy policy Read privacy policy
Security FAQ.
Are you SOC 2 certified?
Our infrastructure providers (Supabase, Google Cloud, Cloudflare) are SOC 2 certified. We inherit their security controls and are evaluating our own certification timeline as we scale.Where is my data stored?
Your data is stored on Supabase's infrastructure, backed by Google Cloud's SOC 2 and ISO 27001 certified data centers. We use regional isolation to ensure data stays in appropriate jurisdictions.Can I request my data be deleted?
Yes. Contact security@trakkr.ai and we'll process your deletion request within 30 days per GDPR requirements. We'll confirm once complete.Do you share data with third parties?
No. We never sell your data. We use essential sub-processors only to provide the service (listed in our privacy policy). Your brand data is never used to train AI models.What happens if there's a breach?
We have incident response procedures in place. In the unlikely event of a breach, we'll notify affected users within 72 hours as required by GDPR, with full transparency about what happened and what we're doing.
Questions about security?
We're happy to discuss our security practices, answer questionnaires, or address specific concerns.
security@trakkr.ai We typically respond within 24 hours.