- Organisation and persona category
- Request-volume and team-size bands
- System categories
- Operational pain categories
- Business contact details
- A short workflow description without personal data
Security boundary · Pre-launch
No live request data belongs on this website.
Trace is validating a future managed data-rights operating model. The public site collects limited qualification information; it is not a production case intake or secure evidence-transfer channel.
Public submission boundary
Operating categories in. Case data out.
The website exists to understand the organisation, workflow and commercial interest. It does not appoint Trace, authorise access or start case work.
- Request contents or requester identities
- Identity documents
- Customer records or exports
- Credentials, API keys or connector secrets
- Case evidence or attachments
- Any other live request personal data
Implemented and evidenced now
Controls for the public validation website.
These controls protect the current website and lead flow. They are not evidence of a production case-data environment.
Request boundary
No public uploads, payment collection or live request-content intake.
Write endpoints
Same-origin checks, explicit origin allowlisting, strict JSON parsing and bounded request sizes.
Abuse resistance
In-memory rate limiting as defence in depth and idempotency keys for lead delivery.
Lead delivery
Durable first-party database storage; any optional lead notification uses an authenticated HTTPS webhook.
Analytics
Cookieless first-party categorical measurement may run before a choice; Google Analytics and persistence wait for opt-in, and a Necessary-only choice stops measurement.
Commercial events
Authenticated server-only events use an opaque reference and no free-text data column.
Browser posture
Security headers are configured for the deployed public site.
Current non-claims
A public page is not assurance evidence.
Trace does not currently publish evidence for the following statements and will not imply them through badges or vague security language.
SOC 2 or ISO 27001 certification
Hosting restricted to European Union regions
A proven production case-data environment
A generally available connector security model
An operative public DPA or subprocessor list
A completed retention and secure-delivery process
A mature incident-response programme
A formal vulnerability-disclosure process
Required before live processing
The go-live gate is evidence, not intent.
No live request data should be accepted until every relevant item is approved, implemented and evidenced for the specific scope.
- 01
Legal authority
Named service provider and accountable owners, accepted scope, controller/processor roles, operative terms and a DPA where applicable.
- 02
Approved data path
A reviewed transfer method, scoped and revocable source access, tenant separation, secrets handling and role-based access.
- 03
Data lifecycle
Retention, backup treatment, deletion, return and access-revocation procedures with usable evidence.
- 04
Delivery and suppliers
Secure pack delivery, access expiry, subprocessor disclosure and transfer-location review.
- 05
Response ownership
Incident and vulnerability contacts, a named authorised customer reviewer and confirmed Trace delivery capacity.
- 06
Rehearsal evidence
A synthetic end-to-end dry run including access revocation and deletion evidence.
Human authority
Preparation can be delegated. Authority cannot be assumed.
The proposed operating model makes the review boundary visible. Trace may prepare evidence and expose uncertainty; an authorised privacy professional and the controller retain the decisions.
Source manifest and two open exceptions carried forward.
No automatic legal decision, delivery or deletion is represented.
Security contact
Ask before sharing.
Use the general contact address for pre-contract security questions. Do not email vulnerabilities, credentials, exports or personal request data until Trace confirms an appropriate supported channel.
No dedicated security mailbox or vulnerability-reporting channel is claimed yet.
Security before access
Discuss the boundary before the data path.
Describe the operating and security requirements without sending request data, identities, exports or credentials.