Skip to content

Security & trust

Enterprise buyers ask where data lives and who changed what.

Trakitup separates the marketing site from the product service. Sessions, roles, integrations, and audit events live on the backend your workspace uses — built by a team that has shipped in regulated industries.

Overview

What we document today

Factual controls — not a certification badge wall.

Data hosting

Workspace data is stored in PostgreSQL on infrastructure chosen for production deployments. The marketing site does not hold your task content or credentials.

Backups & recovery

Database backups follow the production policy for your deployment tier. Confirm RPO/RTO expectations with sales for Enterprise agreements.

SSO-ready roles

Sign-in and session cookies are owned by the product service. Project-scoped roles (admin, member, limited member, guest) enforce who can see boards, settings, and integrations.

Audit trail

Material changes write server-side audit events — the browser is not the system of record. Task activity complements the platform trail for delivery forensics.

Flagship background

Trakitup is built by Flagship, with delivery experience in regulated fintech and enterprise environments — where access reviews and change history are table stakes, not upsells.

This page summarizes product architecture and operational practices. Contract-specific DPAs, subprocessor lists, and certification letters are available through sales when you evaluate Enterprise.

Access control

Roles you can explain in a security review

Guests do not inherit admin surfaces. Integration tokens stay with administrators on the backend — not in user profiles or marketing pages.

Read Enterprise for the full role matrix

Audit

See the change on the task; prove it on the server

Priority moves, Git links, and permission changes are visible where teams work — and recorded where compliance teams expect.

Architecture

Product app shows; product service decides

Authentication, authorization, webhooks, and audit logging run on NestJS — Next.js is the UI.

When published, the legal security document complements this overview with contractual language.

Open the security legal document

Security questionnaire or subprocessors list? Contact sales

Evaluate Trakitup with your security team.

Start free for a hands-on review, or contact sales for Enterprise documentation.