← Back to TrakkitTrakkit · Supplier Review Software

Security & data

Version 11 September 2026

A factual view of Trakkit’s current infrastructure and controls, including the limits of our EU-hosting approach.

Hosting and location

Our application workloads, databases and primary storage are configured in Railway’s Amsterdam region. Deployment checks enforce this region. This does not mean every supporting operation stays in the EU: global edge networking, service logs, support access and external providers can involve international processing. We do not offer an EU-only guarantee for every data flow.

Access and isolation

Users sign in through time-limited email links. The app uses authenticated sessions and role-based permissions; reviewers receive a scoped invitation link instead of management access. Backend queries enforce workspace boundaries. Published form versions are immutable, so existing reviews retain their questionnaire context. These application controls are not a claim of physically separate servers per customer.

Transport, storage and secrets

Public production endpoints use HTTPS/TLS. Provider credentials are kept in runtime configuration and are not included in browser code or exports. Storage protection relies on the hosting platform. Ask us for current encryption-at-rest evidence if your policy requires it; this page does not certify that configuration. Trakkit does not offer customer-managed encryption keys or end-to-end encrypted review storage. See Railway’s security documentation for its controls.

Backups and recovery

Production database and storage backup schedules are configured daily, weekly and monthly. Backups were checked during the Amsterdam migration and release preparation. Recovery is an operator-managed process. No contractual recovery-point, recovery-time or uptime SLA is included in Start or Growth. Ask us about your requirements before relying on a specific recovery window.

Providers and data flows

  • Railway: application, PostgreSQL, primary storage and infrastructure operations. Amsterdam workloads; international processing remains possible under its DPA.
  • Lettermint: transactional email delivery. EU-based processing according to its provider information; recipient mailbox location is separate.
  • OpenAI: optional form generation, adjustment and review summaries. The current integration carries no Trakkit commitment to EU-only inference or zero retention.
  • Mollie: payment processing and subscription-payment references. Card details are handled by the payment provider.
  • HubSpot: business enquiries and follow-up CRM. Our portal is configured for EU hosting; provider exceptions may apply.
  • Microsoft 365: the support@trakkit.eu support mailbox. We have not verified its tenant data location and do not describe it as EU-only.

Providers for our own payment and business-contact administration can have independent controller responsibilities. See the privacy notice and processing terms for the distinction.

Export, retention and incident contact

Results export as PDF, Excel and CSV. Detailed exports can include personal information, and free text may identify people even without names. Workspace deletion is handled through a verified request, not automatically when the subscription expires. Report a suspected incident to support@trakkit.eu with the workspace, time and description; do not email passwords or private invitation links. We investigate, contain incidents and notify affected customer organisations without undue delay when their personal data is breached.

Assurance

Trakkit does not claim ISO 27001 certification, a SOC 2 report or independent penetration-test certification. Provider certifications do not certify Trakkit. Contact us for available evidence and the current configuration before agreeing additional security requirements.

Subscription terms · Privacy notice · Data processing · Security & data