TRUST & DATA PRIVACY

Enterprise-Grade
Security & Privacy

Your data is protected by industry-leading security practices and a privacy-first architecture. We earn trust through transparency, encryption, and strict access accountability.

Zero Keystroke Logging
TLS 1.3 Encryption
Tamper-Evident Logs
SOC 2 Aligned
Controls aligned with SOC 2: security, availability, confidentiality, and data privacy.
GDPR Aligned
Data minimization, retention policies, and user privacy rights aligned with EU & UK standards.
HIPAA Compatible
Configurations that support strict healthcare privacy requirements and BAA safeguards.
ISO 27001 Aligned
Information security management aligned with ISO 27001 best practices and operational controls.
DEFENSE IN DEPTH

Every Layer Secured

From native desktop binaries to cloud databases, every component of Track Beacon is architected security-first.

Encryption in Transit

All telemetry and screenshots are encrypted in transit using TLS 1.3. Passwords are securely hashed with bcrypt.

Role-Based Access Control

Granular permissions ensure users and managers only access authorized data relevant to their direct reports.

SOC 2-Aligned Controls

Engineered following strict SOC 2 principles: confidentiality, integrity, availability, and privacy.

Tamper-Evident Audit Trails

Administrative configuration changes are cryptographically logged with actor, timestamp, and IP address.

Brute-Force & Bot Defense

Intelligent rate limiting, Cloudflare Turnstile bot verification, and automated IP blocking defend against credential stuffing.

OAuth 2.0 & Session Security

Google OAuth 2.0 with refresh-token rotation and instant session revocation upon password or email updates.

Tenant-Scoped Data Isolation

Strict organizational boundary checks block cross-tenant visibility, validated continuously by automated test suites.

Employee Privacy Controls

Configurable screenshot blur, optional desktop capture, and aggregate-only modes ensure high organizational trust.

DATA PRIVACY

How We Protect Your Data

Data Encryption

  • TLS 1.3 encryption in transit
  • Passwords salted & hashed with bcrypt
  • Backend-only storage credentials
  • Short-lived, signed media URLs (expire in 300s)

Access Control

  • Multi-factor authentication (TOTP)
  • Strict role-based access control (RBAC)
  • Refresh-token rotation & reuse detection
  • Instant session termination on credential change

Audit & Monitoring

  • Tamper-evident hash-chained admin logs
  • Intelligent rate-limiting & IP blocking
  • Cloudflare Turnstile bot verification
  • Automated integrity check verification
DEVSECOPS

Secure by Architectural Design

Track Beacon enforces strict automated security tests across every code commit, including multi-tenant isolation validation and role permission regression checks.

We maintain an active responsible disclosure bug bounty program. Report a vulnerability privately — valid submissions are eligible for reward recognition.

Our cloud infrastructure is fronted by Cloudflare’s global edge network, ensuring instant DDoS mitigation, web application firewall filtering, and TLS termination.

Automated Security Tests77+ Passed
Rate-Limited Endpoints20+ Active
Audited Admin Actions60+ Events
Signed Media URL Lifespan300 Seconds

Start securing your
workforce data

Get the visibility you need with the security and compliance your enterprise demands.