Security boundary · Pre-launch

No live request data belongs on this website.

Trace is validating a future managed data-rights operating model. The public site collects limited qualification information; it is not a production case intake or secure evidence-transfer channel.

Public submission boundary

Operating categories in. Case data out.

The website exists to understand the organisation, workflow and commercial interest. It does not appoint Trace, authorise access or start case work.

May be submitted
  • Organisation and persona category
  • Request-volume and team-size bands
  • System categories
  • Operational pain categories
  • Business contact details
  • A short workflow description without personal data
Must never be submitted here
  • Request contents or requester identities
  • Identity documents
  • Customer records or exports
  • Credentials, API keys or connector secrets
  • Case evidence or attachments
  • Any other live request personal data

Implemented and evidenced now

Controls for the public validation website.

These controls protect the current website and lead flow. They are not evidence of a production case-data environment.

Request boundary

No public uploads, payment collection or live request-content intake.

Write endpoints

Same-origin checks, explicit origin allowlisting, strict JSON parsing and bounded request sizes.

Abuse resistance

In-memory rate limiting as defence in depth and idempotency keys for lead delivery.

Lead delivery

Durable first-party database storage; any optional lead notification uses an authenticated HTTPS webhook.

Analytics

Cookieless first-party categorical measurement may run before a choice; Google Analytics and persistence wait for opt-in, and a Necessary-only choice stops measurement.

Commercial events

Authenticated server-only events use an opaque reference and no free-text data column.

Browser posture

Security headers are configured for the deployed public site.

Current non-claims

A public page is not assurance evidence.

Trace does not currently publish evidence for the following statements and will not imply them through badges or vague security language.

SOC 2 or ISO 27001 certification

Hosting restricted to European Union regions

A proven production case-data environment

A generally available connector security model

An operative public DPA or subprocessor list

A completed retention and secure-delivery process

A mature incident-response programme

A formal vulnerability-disclosure process

Required before live processing

The go-live gate is evidence, not intent.

No live request data should be accepted until every relevant item is approved, implemented and evidenced for the specific scope.

  1. 01

    Legal authority

    Named service provider and accountable owners, accepted scope, controller/processor roles, operative terms and a DPA where applicable.

  2. 02

    Approved data path

    A reviewed transfer method, scoped and revocable source access, tenant separation, secrets handling and role-based access.

  3. 03

    Data lifecycle

    Retention, backup treatment, deletion, return and access-revocation procedures with usable evidence.

  4. 04

    Delivery and suppliers

    Secure pack delivery, access expiry, subprocessor disclosure and transfer-location review.

  5. 05

    Response ownership

    Incident and vulnerability contacts, a named authorised customer reviewer and confirmed Trace delivery capacity.

  6. 06

    Rehearsal evidence

    A synthetic end-to-end dry run including access revocation and deletion evidence.

Human authority

Preparation can be delegated. Authority cannot be assumed.

The proposed operating model makes the review boundary visible. Trace may prepare evidence and expose uncertainty; an authorised privacy professional and the controller retain the decisions.

ILLUSTRATIVE CONTROL PATTERN
Trace preparesEvidence structured

Source manifest and two open exceptions carried forward.

Authorised review boundary
Professional decidesDisclosure and erasure pending

No automatic legal decision, delivery or deletion is represented.

Security contact

Ask before sharing.

Use the general contact address for pre-contract security questions. Do not email vulnerabilities, credentials, exports or personal request data until Trace confirms an appropriate supported channel.

Current contacthello@usetrace.eu

No dedicated security mailbox or vulnerability-reporting channel is claimed yet.

Security before access

Discuss the boundary before the data path.

Describe the operating and security requirements without sending request data, identities, exports or credentials.