Trust & Safety

Platform Security

How Traxivo protects your data and your organisation. Security is the foundation everything else is built on.

Last reviewed: April 2026  ·  Found a vulnerability? corporate@traxivo.io

Summary: Traxivo is built on a cloud-native, multi-tenant architecture with strict per-tenant data isolation. All data is encrypted in transit and at rest. We use least-privilege, typically read-only access for any services you connect. SOC 2 Type II is on our roadmap, and GDPR compliance is applied from day one.

Security Posture

Security at Traxivo is a cross-functional discipline. Our engineering, product, and operations teams are aligned on a security-first approach that prioritises data isolation, least-privilege access, and transparency with customers.

Our current security posture covers the following pillars:

  • Production-grade infrastructure security on AWS with isolated networking per environment;
  • End-to-end encryption for all data in transit and at rest;
  • Strict per-tenant data isolation at both the infrastructure and application layers;
  • Least-privilege, typically read-only access for any third-party services you choose to connect;
  • Continuous monitoring and anomaly detection on platform infrastructure;
  • GDPR compliance applied from day one of platform development.

Infrastructure Security

Cloud Provider

Traxivo is deployed on Amazon Web Services (AWS), which maintains a comprehensive set of compliance certifications including SOC 1/2/3, ISO 27001, PCI DSS, and FedRAMP. AWS infrastructure security documentation is available at aws.amazon.com/security.

Network Isolation

Production, staging, and development environments are fully isolated in separate VPCs (Virtual Private Clouds) with no cross-environment access paths. All inbound traffic is routed through load balancers with WAF (Web Application Firewall) rules enabled. Direct access to databases or internal services is not possible from the internet.

Availability

The Traxivo platform is deployed across multiple availability zones to ensure resilience against single-zone failures. Automated failover and health checks are in place for all critical services.

Vulnerability Management

We perform regular dependency scanning, static analysis, and infrastructure vulnerability assessments. Critical security patches are applied within 24 hours. Non-critical patches are applied within the next scheduled deployment cycle.

Data Protection

Encryption in Transit

All data transmitted between your systems and the Traxivo platform is encrypted using TLS 1.2 or higher. We enforce HTTPS on all endpoints and use HSTS (HTTP Strict Transport Security). Connections using deprecated TLS versions are rejected.

Encryption at Rest

All Customer Data stored on Traxivo infrastructure is encrypted at rest using AES-256. Database encryption is enabled at the storage layer. Encryption keys are managed using AWS KMS with automatic rotation.

Tenant Isolation

Each Traxivo customer account operates in a fully isolated tenant environment. Tenant identifiers are enforced at the API, application, and database layers. It is architecturally impossible for one tenant to access another tenant’s data. This isolation is tested as part of every release cycle.

Backups

Customer Data is backed up daily with point-in-time recovery enabled for databases. Backups are encrypted and stored in geographically redundant locations. Backup integrity is verified regularly through automated restoration tests.

Access Control

Customer-Facing Access

Traxivo supports role-based access control (RBAC) within customer accounts. Account administrators can assign roles (admin, member, read-only) to individual users and revoke access at any time. All access changes are recorded in an audit log.

Traxivo Staff Access

Access to production systems by Traxivo staff is governed by a strict least-privilege policy. No Traxivo employee has standing access to Customer Data. Production access requires approval through an access management system, is time-limited, and is fully logged. We maintain an internal audit of all staff production access.

Authentication

Traxivo supports secure authentication via email and password with bcrypt hashing, and single sign-on (SSO). Session tokens are short-lived and automatically rotated. Multi-factor authentication (MFA) is supported and recommended for all users.

Third-Party Integrations

Traxivo only accesses third-party services that you explicitly choose to connect to your account. Our approach is built around least privilege and customer control.

  • We request the minimum permissions required, and these are typically read-only;
  • We retain only the limited, structured information needed to provide the Services, and we do not retain raw message content, files, or source material;
  • You control which services are connected, and you can revoke access at any time from your account settings or from within the third-party service;
  • Revoking access immediately stops any further data access from that source.

Compliance & Certifications

StandardStatusNotes
GDPR (EU)CompliantApplied from day one. DPA available on request.
UK GDPRCompliantFollows the same framework as EU GDPR.
CCPA (California)CompliantNo sale of personal data. Data subject rights supported.
SOC 2 Type IIRoadmapTargeted for Enterprise tier launch. Controls are in place; audit in preparation.
ISO 27001RoadmapPlanned following SOC 2 completion.
HIPAANot certifiedTraxivo is not currently HIPAA-certified. Do not process PHI through the platform.

Enterprise customers may request our current security posture documentation, data processing agreements, and sub-processor list by contacting corporate@traxivo.io.

Incident Response

Traxivo maintains a formal incident response plan covering detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed security incident affecting Customer Data:

  • We will notify affected customers within 72 hours of becoming aware of a breach, in accordance with GDPR Article 33;
  • Notification will include: the nature of the incident, categories of data involved, likely consequences, and remediation steps taken;
  • We will cooperate fully with any regulatory investigation and provide all reasonable assistance to affected customers;
  • A post-incident review will be conducted and findings shared with affected customers upon request.

To report a suspected security incident affecting your account, contact corporate@traxivo.io immediately.

Responsible Disclosure

Traxivo welcomes reports from security researchers and the broader community. If you believe you have found a vulnerability in our platform or infrastructure, please report it responsibly:

How to report:
Email: corporate@traxivo.io
Please include: affected URL or component, description of the vulnerability, steps to reproduce, potential impact, and your contact information.

Our commitments: We will acknowledge your report within 5 business days, investigate promptly, keep you informed of our progress, and not pursue legal action against researchers acting in good faith.

Please do not access, modify, or delete Customer Data belonging to other accounts during your research. Do not perform automated scanning or DoS testing against production systems without prior written approval.

Contact Security

Traxivo Security Team
Vulnerabilities & incidents: corporate@traxivo.io
Privacy questions: corporate@traxivo.io