Security

Built for money that has to add up

How Traxle keeps each administrator’s data separate, its financial history intact, and access deliberate.

Tenant isolation in the database

Every table that holds a workspace’s records carries its tenant, and Postgres row-level security enforces it, not the application alone. A request can only read its own workspace’s rows, so even a query that forgets to filter never returns another administrator’s data. The guarantees are tested by attempting to break them.

An append-only ledger

The application’s database role cannot update or delete a ledger entry. A correction is a reversing entry with a reason, so the history of every dollar remains.

Deliberate access

Permissions are data, granted through roles your admins can see and change. Adjusters carry an explicit money authority. Each role sees fields through its own view, so a dealer sees what a dealer should. Every grant and change is written to an audit trail.

Data protection

Hosted in the EU, in Ireland, on managed Postgres. Encrypted in transit and at rest. Documents live in a private bucket, are checksummed on upload, and are served through short-lived signed links.

Accounts and sessions

An account confirms its email address before it can be used. Sessions are verified on every request, and a person holds a separate membership in each administrator they work with.

Operations

Credentials live in a secrets manager, never in code or on disk. Background work is authenticated and recorded, and a failure is never reported as success.

What we do not claim yet

Traxle does not yet hold SOC 2 or ISO 27001 certification. If your due diligence needs more than this page, ask, and we will answer in writing.

Ask us

Reporting a vulnerability

Send the details through the demo request form and say it is a security report. We will respond, and we ask that you give us reasonable time to fix an issue before disclosing it.

See it on a book like yours

Thirty minutes with the people who build Traxle: a contract issued, a claim authorized, and the ledger behind both.