Trackwise LLC operates as a regulated Money Services Business. Security is foundational to our platform. This page summarizes the controls in place.
1. Encryption
- In transit: TLS 1.2 minimum. TLS 1.3 preferred. HSTS enabled.
- At rest: AES-256 for production data stores and backups.
- Application keys: Managed in a centralized secrets vault. Rotation per policy.
2. Access control
- Single sign-on (SSO) with mandatory multi-factor authentication (MFA) for all production access.
- Least-privilege role-based access. Privileged actions require approval.
- Quarterly access reviews.
3. Application security
- SAST and SCA on every pull request.
- Dependency vulnerability monitoring with bounded remediation SLAs.
- Annual third-party penetration tests of customer-facing systems.
4. Infrastructure
- Production workloads run in AWS U.S. regions.
- Network isolation via VPC, private subnets, security groups, and WAF.
- Centralized logging and monitoring with anomaly detection.
- Backups tested on a regular cadence. Documented disaster-recovery plan.
5. Card data
Trackwise does not store full PAN, CVV, or sensitive authentication data on its own infrastructure. Card data is tokenized and stored within the PCI-DSS-scoped systems of our card processor / issuer partner. Trackwise minimizes its PCI scope by relying on iframe / hosted-fields integrations and tokenized references.
6. Vendors and subprocessors
Vendors and subprocessors that process personal or payment data are subject to security and privacy review before onboarding and reviewed annually. A list of subprocessors is available on request via security@trackwise.finance.
7. Incident response
Trackwise maintains a documented incident-response plan. Confirmed incidents impacting customer data are communicated to affected customers in accordance with applicable law.
8. Independent assessments
Trackwise is engaged in the path toward SOC 2 Type II. Status updates are available on request to security@trackwise.finance.
9. Reporting a vulnerability
If you believe you have found a security vulnerability in Trackwise, please email security@trackwise.finance with details, steps to reproduce, and your contact information. We appreciate coordinated disclosure and will not pursue good-faith researchers who comply with our coordinated disclosure terms.