Skip to main content

Security & Trust

Traceable is built for regulated industries where data integrity, confidentiality, and regulatory compliance are not optional. This section documents the security architecture, data handling practices, and compliance posture of the platform.


Summary

AreaImplementation
Data residencyEU infrastructure (Ireland + Germany); the only non-EU processing is opt-in Document AI content to Anthropic (US) under EU SCCs
Encryption at restAES-256 via Supabase / AWS KMS
Encryption in transitTLS 1.3 on all connections
AuthenticationSupabase Auth; bcrypt password hashing; OTP support
API securityBearer token authentication; HMAC signing for BMS webhooks
Rate limitingUpstash Redis sliding-window limits on all endpoints
Access controlRow-Level Security (RLS) at database layer; RBAC at application layer
GDPRArticle 15/17/20 rights implemented; DPA available on request
Audit loggingAll create/update/delete/publish events logged with actor, timestamp, and resource
Sub-processors6 sub-processors; all EU-resident except Anthropic (US), used only for opt-in Document AI under EU SCCs

In This Section

PageContents
InfrastructureHosting architecture, cloud providers, EU data residency guarantee
Data EncryptionAES-256 at rest, TLS 1.3 in transit, key management
GDPR ImplementationData subject rights (Articles 15, 17, 20), lawful bases, retention
Sub-processorsComplete register of third-party data processors
Vulnerability DisclosureHow to report security issues; response SLA

Security Contacts

For security vulnerabilities: see the Vulnerability Disclosure policy.

For GDPR requests or DPA enquiries: support@traceable.digital

For general security questions: support@traceable.digital