Skip to content
PricingDocs

Trust Center

Transparency is not optional when you process device signals at scale. Here is everything you need to evaluate tracio.ai's security posture.

Security Architecture

Encryption Architecture

Verified

Device identification signal payloads are encrypted end-to-end before transit, then wrapped in AES-256-GCM for transport. At rest, all visitor data is encrypted with AES-256. API keys are bcrypt-hashed and never stored in plaintext.

Privacy by Architecture

Verified

tracio.ai collects device signals, not personal data. All signals are hashed client-side using one-way hashing before transmission. No names, emails, browsing history, or cross-site tracking. Visitor IDs are one-way hashes that cannot be reversed.

Data Sovereignty

Verified

Choose EU or US data residency at account creation. Visitor data never leaves your selected region. No cross-region replication, no third-party data sharing, no secondary data monetization. You own every byte.

Access Control

Verified

Least-privilege RBAC with scoped API keys, IP allowlisting, and mandatory MFA for admin accounts. Enterprise plans include SSO/SAML integration with Okta, Auth0, and Azure AD.

Audit Trail

Verified

Comprehensive audit logging covers every API call, configuration change, key rotation, and admin action. Logs are immutable, exportable, and retained for 12 months. Enterprise plans include SIEM integration.

Incident Response

Active

24/7 automated monitoring with PagerDuty escalation. Documented incident response runbooks with severity classification (P0-P3). Mean time to acknowledge: 5 minutes. Mean time to resolve: 2 hours.

Certifications & Compliance

SOC 2 Type II

Certified

Annual audit covering security, availability, and confidentiality

Last: January 2026

GDPR

Compliant

Full compliance with EU General Data Protection Regulation

Last: Ongoing

CCPA

Compliant

Meets California Consumer Privacy Act requirements

Last: Ongoing

ISO 27001

In Progress

Information security management system certification

Last: Q2 2026

Available Documents

Request any document below by contacting security@tracio.ai

Data Processing Agreement (DPA)

Legal

Available

SOC 2 Type II Report

Audit

Available

Penetration Test Summary

Security

Available

Privacy Impact Assessment

Privacy

Available

Subprocessor List

Legal

Available

Security Whitepaper

Technical

Available

Need More Detail?

Our security team is available for calls, questionnaire completion, and custom compliance reviews.