Security
Last updated 20 September 2026
How TrakIntel encrypts, hosts, restricts and monitors the data it holds, and how to reach us if you find a problem with any of it.
Encryption
Data in transit is protected by HTTPS, enforced via TLS 1.3. Data is encrypted using AES-256-GCM, which is 256-bit symmetric key encryption with Galois/Counter Mode. Our certificates are X.509, issued by Let's Encrypt and Sectigo, with RSA 2048-bit public keys and SHA-256 signatures.
Infrastructure
TrakIntel stores and processes EU personal data within the EU and EEA. Our platform runs on a self-hosted MongoDB database, hosted with Hetzner, across two separate servers with active redundancy and failover between them.
Our AI agent processing runs on foundation models that TrakIntel self-hosts and fine-tunes: one open-source foundation model based on OpenAI's open-weight model family, and one based on Google's open-weight model family. Both run entirely on TrakIntel's own infrastructure. No personal data is processed through either model, and because neither is called through an external API, the underlying data does not leave our infrastructure to generate these outputs.
We also use the following third-party services:
- Microsoft Azure, India region, used to generate vector embeddings — numerical representations of text — for platform search and matching. Per our internal assessment, this does not process personal data.
- Google Analytics, used for visitor analytics on our marketing site only, not the product platform, and processed on Google's EU-based infrastructure per our current understanding. Because this involves cookies and IP address processing, which the GDPR treats as personal data, we obtain explicit consent before setting these cookies.
Access control
Internal staff access to customer and platform data is controlled through multi-factor authentication and role-based access control. Data is stored encrypted.
Incident response
If a security incident affecting personal data occurs, TrakIntel will assess it and, where required, notify the relevant supervisory authority within 72 hours as required by Article 33 GDPR, and notify affected customers without undue delay under Article 34 GDPR where the incident poses a high risk to individuals.
Our internal target is to begin containing and investigating a security incident within 72 hours of becoming aware of it.
Backups and continuity
The platform runs across two separate servers with active redundancy and failover between them.
Sub-processor security
Providers who process data on our behalf are covered under the same data protection commitments described in the sub-processors section of our Privacy Policy.
Reporting a security issue
Security concerns and questions can be reported to security@trakintel.ai.
These four documents describe the same facts and are kept in step with each other.