Security overview
Practical safeguards, stated plainly.
Last reviewed
25 July 2026
Identity and access
Password hashing, managed sessions, optional MFA, role permissions, tenant-scoped application access and revocable hashed API keys.
Data protection
TLS for browser and API traffic, managed-provider storage protection and additional application encryption for selected high-risk secrets.
Abuse controls
Endpoint and edge rate limits, validation, authenticated writes, audit events and operational diagnostics where configured.
Proof storage
Production uploads use durable object storage and access-controlled asset delivery rather than relying on an application container's temporary disk.
1. Scope and assurance status
This is a public overview, not an audit report, penetration-test result, service-level agreement or warranty. Trackely does not currently claim ISO 27001, SOC 2, Cyber Essentials or another formal security certification unless a customer receives separate written evidence. Security is risk reduction, not a guarantee that an incident cannot occur.
2. Application safeguards
- authenticated sessions, password hashing and optional multi-factor authentication;
- role and tenant checks intended to prevent one customer accessing another's records;
- hashed, scoped and revocable API credentials;
- input validation, rate limits and additional controls on sensitive or high-volume endpoints;
- audit events for many security-relevant actions, with coverage reviewed as the product changes; and
- limited logging of secrets and sensitive message content by design.
3. Hosting, encryption and environments
The production service uses managed cloud hosting, database and object-storage providers. Browser and API traffic uses HTTPS/TLS. Provider-level storage encryption protects routine data at rest; selected application secrets receive additional application-layer encryption. Development and production practices are separated and administrative access is limited to operational need.
4. Availability, backup and recovery
Trackely uses durable managed services for production data, but backup schedules, retention, restore points and regional redundancy depend on the active provider configuration and commercial plan. Unless a signed agreement states exact recovery objectives, we do not promise point-in-time recovery, multi-region failover, a particular backup period or uninterrupted availability. Customers should retain source records and continuity procedures proportionate to their operation.
5. Monitoring and incident response
Rate limits, application logs, error reporting and infrastructure alerts are used where configured to investigate security and reliability events. Trackely assesses suspected incidents, contains and remediates them, preserves appropriate records and makes contractual or legal notifications. Processor breach commitments are in the DPA.
6. Data lifecycle and subprocessors
Export, retention, erasure and anonymisation workflows support lifecycle management. Their scope depends on the record type, customer configuration, legal holds and backup expiry. Providers that may process Customer Personal Data are identified in the Subprocessor Register.
7. Customer responsibilities
- Use unique accounts, MFA where appropriate, least-privilege roles and prompt offboarding.
- Keep devices, inboxes, API keys and connected systems secure.
- Review exports, public tracking settings, recipient links and integration permissions.
- Do not put unnecessary sensitive data into notes, files, proofs or AI prompts.
- Report suspected compromise promptly and maintain suitable business-continuity plans.
8. Report a vulnerability or incident
Email support@trackely.co.uk with the affected URL or feature, impact, reproduction steps and a safe way to contact you. Do not include live personal data or secrets in the first message. Good-faith research rules are in our Acceptable Use Policy. For an active account compromise, say “urgent security incident” in the subject.