Summary: Traxivo is built on a cloud-native, multi-tenant architecture with strict per-tenant data isolation. All data is encrypted in transit and at rest. We use least-privilege, typically read-only access for any services you connect. SOC 2 Type II is on our roadmap, and GDPR compliance is applied from day one.
Security Posture
Security at Traxivo is a cross-functional discipline. Our engineering, product, and operations teams are aligned on a security-first approach that prioritises data isolation, least-privilege access, and transparency with customers.
Our current security posture covers the following pillars:
- Production-grade infrastructure security on AWS with isolated networking per environment;
- End-to-end encryption for all data in transit and at rest;
- Strict per-tenant data isolation at both the infrastructure and application layers;
- Least-privilege, typically read-only access for any third-party services you choose to connect;
- Continuous monitoring and anomaly detection on platform infrastructure;
- GDPR compliance applied from day one of platform development.
Infrastructure Security
Cloud Provider
Traxivo is deployed on Amazon Web Services (AWS), which maintains a comprehensive set of compliance certifications including SOC 1/2/3, ISO 27001, PCI DSS, and FedRAMP. AWS infrastructure security documentation is available at aws.amazon.com/security.
Network Isolation
Production, staging, and development environments are fully isolated in separate VPCs (Virtual Private Clouds) with no cross-environment access paths. All inbound traffic is routed through load balancers with WAF (Web Application Firewall) rules enabled. Direct access to databases or internal services is not possible from the internet.
Availability
The Traxivo platform is deployed across multiple availability zones to ensure resilience against single-zone failures. Automated failover and health checks are in place for all critical services.
Vulnerability Management
We perform regular dependency scanning, static analysis, and infrastructure vulnerability assessments. Critical security patches are applied within 24 hours. Non-critical patches are applied within the next scheduled deployment cycle.
Data Protection
Encryption in Transit
All data transmitted between your systems and the Traxivo platform is encrypted using TLS 1.2 or higher. We enforce HTTPS on all endpoints and use HSTS (HTTP Strict Transport Security). Connections using deprecated TLS versions are rejected.
Encryption at Rest
All Customer Data stored on Traxivo infrastructure is encrypted at rest using AES-256. Database encryption is enabled at the storage layer. Encryption keys are managed using AWS KMS with automatic rotation.
Tenant Isolation
Each Traxivo customer account operates in a fully isolated tenant environment. Tenant identifiers are enforced at the API, application, and database layers. It is architecturally impossible for one tenant to access another tenant’s data. This isolation is tested as part of every release cycle.
Backups
Customer Data is backed up daily with point-in-time recovery enabled for databases. Backups are encrypted and stored in geographically redundant locations. Backup integrity is verified regularly through automated restoration tests.
Access Control
Customer-Facing Access
Traxivo supports role-based access control (RBAC) within customer accounts. Account administrators can assign roles (admin, member, read-only) to individual users and revoke access at any time. All access changes are recorded in an audit log.
Traxivo Staff Access
Access to production systems by Traxivo staff is governed by a strict least-privilege policy. No Traxivo employee has standing access to Customer Data. Production access requires approval through an access management system, is time-limited, and is fully logged. We maintain an internal audit of all staff production access.
Authentication
Traxivo supports secure authentication via email and password with bcrypt hashing, and single sign-on (SSO). Session tokens are short-lived and automatically rotated. Multi-factor authentication (MFA) is supported and recommended for all users.
Third-Party Integrations
Traxivo only accesses third-party services that you explicitly choose to connect to your account. Our approach is built around least privilege and customer control.
- We request the minimum permissions required, and these are typically read-only;
- We retain only the limited, structured information needed to provide the Services, and we do not retain raw message content, files, or source material;
- You control which services are connected, and you can revoke access at any time from your account settings or from within the third-party service;
- Revoking access immediately stops any further data access from that source.
Compliance & Certifications
| Standard | Status | Notes |
|---|---|---|
| GDPR (EU) | Compliant | Applied from day one. DPA available on request. |
| UK GDPR | Compliant | Follows the same framework as EU GDPR. |
| CCPA (California) | Compliant | No sale of personal data. Data subject rights supported. |
| SOC 2 Type II | Roadmap | Targeted for Enterprise tier launch. Controls are in place; audit in preparation. |
| ISO 27001 | Roadmap | Planned following SOC 2 completion. |
| HIPAA | Not certified | Traxivo is not currently HIPAA-certified. Do not process PHI through the platform. |
Enterprise customers may request our current security posture documentation, data processing agreements, and sub-processor list by contacting corporate@traxivo.io.
Incident Response
Traxivo maintains a formal incident response plan covering detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed security incident affecting Customer Data:
- We will notify affected customers within 72 hours of becoming aware of a breach, in accordance with GDPR Article 33;
- Notification will include: the nature of the incident, categories of data involved, likely consequences, and remediation steps taken;
- We will cooperate fully with any regulatory investigation and provide all reasonable assistance to affected customers;
- A post-incident review will be conducted and findings shared with affected customers upon request.
To report a suspected security incident affecting your account, contact corporate@traxivo.io immediately.
Responsible Disclosure
Traxivo welcomes reports from security researchers and the broader community. If you believe you have found a vulnerability in our platform or infrastructure, please report it responsibly:
How to report:
Email: corporate@traxivo.io
Please include: affected URL or component, description of the vulnerability, steps to reproduce, potential impact, and your contact information.
Our commitments: We will acknowledge your report within 5 business days, investigate promptly, keep you informed of our progress, and not pursue legal action against researchers acting in good faith.
Please do not access, modify, or delete Customer Data belonging to other accounts during your research. Do not perform automated scanning or DoS testing against production systems without prior written approval.
Contact Security
Traxivo Security Team
Vulnerabilities & incidents: corporate@traxivo.io
Privacy questions: corporate@traxivo.io