Security & compliance
How TraceGuard protects your data, and the regimes it supports.
Data isolation
TraceGuard is multi-tenant with hard organization isolation enforced by row-level security at the database layer — not just in application code. See Access & multi-tenancy for the model.
Least privilege everywhere
Members, service accounts, and tokens are all scoped, and no principal can be granted more authority than its creator. Tokens are typed and scoped; the API and MCP server are bounded by the same rules as the UI.
Auditability
A tamper-evident audit log records security-relevant actions, and evidence bundles let you produce verifiable proof on demand.
Compliance regimes
TraceGuard is built to help you stay continuously audit-ready for supply-chain
and product-security regimes such as the EU Cyber Resilience Act (CRA), and to
support evidence needs for frameworks like ISO 27001. The cryptography BOM
(cbom) type in particular helps with crypto-agility requirements.
For a current list of certifications, sub-processors, and a security questionnaire, contact your TraceGuard representative.