Trust Center

Security, Privacy & Continuity

This trust center summarizes the current security architecture and the evidence expected for production supplier qualification. It intentionally avoids claiming third-party certifications that have not been obtained.

Tenant isolation

Rev3.0.4 introduced a provisioning architecture designed to give each customer organization a separate operational database and organization-bound authentication context. Production deployment must validate that one tenant cannot select or access another tenant’s database.

Access & records

  • Role-based permissions
  • Organization-scoped authorization
  • Electronic approval and audit-history features
  • HTTPS required by deployment guidance
  • No passwords or database credentials sent by setup email

Backup / disaster recovery

Backup tooling and operational guidance are part of the application package, but customer qualification should require documented backup schedules, off-site copies, restore tests, recovery-point objectives (RPO), recovery-time objectives (RTO), and evidence from completed tests.

RESTORE EVIDENCE REQUIRED

Independent assurance

NOT CURRENTLY CLAIMED

No SOC 2 Type II, ISO 27001, FedRAMP or CMMC certification is claimed here. A penetration-test summary and third-party assurance package should be obtained before high-assurance aerospace/defense deployment.

Do not store CUI or ITAR-controlled technical data in a general TraceGauge environment unless the specific contracted deployment has been reviewed and approved for those requirements.