Security

Operational records deserve explicit boundaries.

Taltrax uses tenant isolation, role-based access, private file storage, audit trails, and Australian hosting for the core data-at-rest path.

What protects your records

Australian data residency

Core database records, private file storage, and backups are hosted in Australia, in the Sydney region.

Tenant isolation

Every request is enforced at the database layer through row-level security tied to operator membership; client-side filters are not treated as the security boundary.

Private uploads

File uploads use short-lived server-authorised paths, private buckets, size and content checks, and operator-scoped access.

Access and integrity

Controls follow the record, not only the screen.

  • Pilot and admin roles with server-authoritative permission checks
  • Append-only audit history for defined operational records
  • Soft-delete and controlled retention instead of casual destructive deletion
  • PKCE authentication and revocation-aware sessions
  • Restricted privileged functions for system-only operations

Response and recovery

Contain, assess, communicate, restore.

Taltrax maintains breach-response, secret-rotation, continuity, legal-request, and restore procedures. When the production PITR gate is active, RPO near-zero and RTO within four hours are operational recovery targets, not availability guarantees.

To report a suspected vulnerability, emailsupport@taltrax.com with “Security” in the subject. Do not include live credentials or sensitive operator records.

Subprocessors and exceptions

Taltrax’s current service path uses Supabase, Vercel, Cloudflare Turnstile, Resend, Stripe in test mode, and OpenAI only when the optional AI checklist feature is enabled. The OpenAI API is called without requesting response storage; a formal zero-data-retention agreement has not yet been executed. ThePrivacy Policy explains current processing and cross-border disclosures.

No analytics vendor is active. PostHog, Plausible, Sentry, and third-party uptime monitoring remain deferred and are not represented as current security or data-processing controls.