Security
← Home

Security Practices

Trailrock works inside partners' own systems and data, so security is a working constraint on every engagement, not a separate policy exercise. This page summarizes the practices that apply across our work.

Client ownership

Code, data, and infrastructure produced during an engagement belong to the client. Trailrock does not retain a copy of client data or systems beyond what an engagement's contract specifies, and does not use client data to train models or build products for other clients.

Access control

Engagement teams work under the principle of least privilege: access to a partner's systems is scoped to what the engagement requires, granted through the partner's own identity and access controls where possible, and reviewed as the engagement's scope changes. Access is revoked at the end of an engagement.

Data handling

Where Trailrock does handle client data directly, for example during a migration or analysis, it is encrypted in transit and at rest, stored in the environment the client specifies (including the client's own cloud tenant where required), and deleted once the engagement work using it is complete.

Internal practices

Trailrock team members use hardware-backed multi-factor authentication, encrypted devices, and a managed identity system for internal and client-facing tools. Vendor access is reviewed periodically, and engagement work is conducted under the confidentiality terms of the client's master services agreement.

Incident response

If Trailrock identifies a security incident affecting a partner's systems or data, we notify the partner without undue delay and work with their team on containment and remediation.

Reporting a concern

If you believe you've found a security issue related to Trailrock's own systems (this site, internal tools), report it to hello@trailrock.com. We'll acknowledge reports and follow up on next steps.