Traceline.

Security & trust

Answers for your security review

The questions an IT security team asks before signing — addressed plainly, reflecting the real implementation. Full technical detail is available under NDA.

Tamper-evident audit

Three hash-linked chains; altering one record breaks verification from that point.

Identity & MFA

SSO (SAML 2.0 / OIDC) with SCIM provisioning, plus password, email codes and authenticator; MFA enforceable.

Tenant isolation

Every record scoped to one organisation and checked on every request.

Encryption in transit

HTTPS with HSTS, a strict content-security-policy, human-verification on every login.

Verified backups

Encrypted, restore-verified on every run, with off-host support.

Data ownership

Full export and account deletion for owners — your data is yours.

  • AuthenticationPassword, email one-time codes, authenticator (TOTP), and SSO via SAML 2.0 or OIDC with SCIM provisioning.
  • Authorisation (RBAC)Capability-based roles checked on every action; organisation- and company-scoped access.
  • Audit chainThree hash-linked chains with verification endpoints; secrets redacted from audit.
  • Encryption & transportHTTPS with HSTS, strict content-security-policy, human-verification on every login.
  • Backups & recoveryEncrypted, restore-verified on every run, off-host support; documented DR runbook.
  • ComplianceSOC 2 / ISO 27001 are on our roadmap — not yet certified. We are happy to review our controls with you today.

Integrations & API: a scoped REST API with key rotation and usage logging, plus SSO for any SAML 2.0 or OIDC identity provider with SCIM provisioning. See the API overview →

See it on your own assets

Book a guided demo, or talk to our team about enterprise terms.