← Back to Homepage

Security

How we protect your data. We describe what is actually in place today, and are plain about what is not.

Infrastructure & certifications

Built on Google Cloud Platform

TraceLock runs entirely on Google Cloud Platform. Google's infrastructure holds SOC 2 Type II, ISO/IEC 27001, and other independent certifications (see the Google Cloud compliance reports). Your data inherits the physical and network security of that platform.

Our own certifications

TraceLock as a company does not yet hold its own SOC 2, ISO 27001, or HIPAA certification, and we do not claim to. We would rather tell you that plainly than imply an audit we have not completed.

What is in place today

Encryption

  • Data encrypted at rest by Google Cloud (AES-256, platform default)
  • All traffic encrypted in transit over HTTPS/TLS

Access & tenant isolation

  • Every record is scoped to your company; tenants cannot see each other's data
  • Role-based access control (field, manager, admin, viewer)
  • Authentication via Firebase Authentication

Audit & monitoring

  • Immutable audit log of create/update/delete actions
  • Application error monitoring (Sentry)
  • Uptime monitoring on the API health endpoint

Data location

  • Hosted and processed in the United States (Google Cloud us-east1)
  • Automated database backups via Google Cloud SQL

Fire safety standards

Built around NFPA workflows

Inspection templates and reports are designed around NFPA standards (including NFPA 10 for portable fire extinguishers) so your records line up with what a fire marshal expects. TraceLock is a record-keeping tool; it does not itself certify your equipment or your company.

Your data, and how to reach us

Your inspection and customer data belongs to you. On request we will export it or delete it. For security questions, data requests, or to report an issue:

Security & privacy: privacy@tracelock.tech

Support: support@tracelock.tech