[ Trust ]

Compliance, Regulations, & Memberships

Data Security

Being in the security business means it’s paramount for TrackTik to develop, implement, and maintain software security best practices. Various methods are deployed to secure your data at all times, including:

  • Data hosted on Amazon Web Services (AWS) cloud servers and according to your region
  • Encryption of all data at REST (SHA-256 ciphers) and in-transit (TLS v1.2+ protocols)
  • Daily full back-ups kept for ten days and redundancy in the same AWS region
  • Key management for encryption controlled through Amazon Key Management Service
Iso Certification Tracktik
Data Lab Custom Dashboards Tracktik

Application Security

TrackTik follows the OWASP SAMM best practices and uses different processes to ensure security stays at the heart of our operations. Here are a few examples of what you should expect with the application:

  • Extensive governance and incident management processes
  • Least privilege principle for access management
  • Possible single sign-on integration and/or strong password requirements for users
  • External penetration tests conducted multiple times a year by experts
  • Strong network perimeter security with best-in-class firewall and IDS
  • Centralized logging, reporting, and analysis of logs to provide visibility, traceability and security insights

Secure Development Process

Secure development and continuous improvements are the essence of TrackTik’s development principles. Processes are in place throughout its SDLC to ensure compliance with current certifications and industry best practices:

  • Check & Balance principles embedded in our processes
  • Change requests are ticketed and peer-reviewed before commit
  • Automatic testing and code scanning of all requests
  • Dedicated environments for development, testing, and production
  • Privacy and security evaluations performed on new modules and features
Security Guard Tracktik
Data Lab Custom Dashboards Tracktik

Corporate Security Standards

TrackTik also implements security controls to guarantee that its corporate standards and employees training are of the highest level. As an example, TrackTik currently has the following processes in place:

  • Continuous employee training and education on security and privacy
  • Specific developer training on security and OWASP top 10 security risks
  • Supplier chain certification review on security
  • Non-disclosure agreements and background checks for all employees and contractors