Security you can prove.

We protect our customers’ data with the same rigor they protect the people and places in their care. Trackforce meets the world’s most demanding security and privacy standards – independently audited, continuously monitored, and led by a dedicated security team.

SOC 2 Type IIISO 27001 / 27017NIST 800-171GDPRCCPAIAPP member

Compliance, regulations & memberships

Independently certified against the standards that matter.

SOC 2 Type II certified

We undergo a yearly audit against SOC 2 Type II security controls to provide best-in-class security for the platform.

ISO 27001 – Information security management

Certified ISO 27001 / IEC 27001:2013 for our information security management system.

ISO 27017 – Cloud security extension

Alongside ISO 27001, we achieved a dedicated cloud security extension through the ISO 27017 standard.

GDPR – General Data Protection Regulation

Committed to staying compliant with GDPR and its privacy requirements. A dedicated data processing agreement is available.

NIST SP 800-171 compliance

NIST 800-171 compliance ensures the protection of Controlled Unclassified Information (CUI) within non-federal systems.

CCPA – California Consumer Privacy Act

On top of the U.S. Privacy Shield, we meet California Consumer Privacy Act data and privacy requirements.

IAPP member

A member of the International Association of Privacy Professionals, benefiting from its global privacy community.

01 – Data security

Your data, secured at every layer.

Being in the security business means it’s paramount to develop, implement, and maintain software security best practices. Multiple methods keep your data protected at all times:

  • Data hosted on Amazon Web Services (AWS) cloud servers, according to your region.
  • Encryption of all data at rest (SHA-256 ciphers) and in transit (TLS v1.2+ protocols).
  • Daily full back-ups kept for ten days, with redundancy in the same AWS region.
  • Key management for encryption controlled through Amazon Key Management Service.
ISO 27001 and ISO 27017 certified secure cloud infrastructure
Trackforce platform dashboards on a tablet

02 – Application security

Security at the heart of the platform.

We follow OWASP SAMM best practices and layer multiple processes to keep security central to every operation. Here’s what you should expect from the application:

  • Extensive governance and incident management processes.
  • Least-privilege principle for access management.
  • Single sign-on integration and/or strong password requirements for users.
  • External penetration tests conducted multiple times a year by experts.
  • Strong network perimeter security with best-in-class firewall and IDS.
  • Centralized logging, reporting, and analysis for visibility and traceability.

03 – Secure development

Built securely, improved continuously.

Processes are embedded throughout our SDLC to keep us compliant with current certifications and industry best practices:

  • Check & balance principles embedded in our processes.
  • Change requests are ticketed and peer-reviewed before commit.
  • Automatic testing and code scanning of all requests.
  • Dedicated environments for development, testing, and production.
  • Privacy and security evaluations performed on new modules and features.

04 – Corporate standards

Security starts with our people.

We implement controls to guarantee our corporate standards and employee training stay at the highest level:

  • Continuous employee training and education on security and privacy.
  • Specific developer training on security and OWASP Top 10 risks.
  • Supplier-chain certification review on security.
  • Non-disclosure agreements and background checks for all employees and contractors.

Have a security or privacy question?

Request our data processing agreement, latest audit reports, or a walkthrough of our security program. Our team is ready to help.