Skip to main content
Features Pricing About Articles
TrackE5
Login Sign up
Features Pricing How It Works About Articles Sign up

Security

Last updated 2 August 2026 · Version V1

On this page

  1. Encryption
  2. How your transactions are processed
  3. Bank connections
  4. Infrastructure
  5. Access control
  6. Secure development
  7. Incident response
  8. Reporting a vulnerability
  9. Compliance

Encryption

Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256.

Encryption keys are managed by Google Cloud Platform on our behalf. TrackE5 is not end-to-end encrypted and is not a zero-knowledge service. Our systems process your transaction data in order to categorise it and produce your budgets and reports. We describe exactly how below, and in our Privacy Policy.

How your transactions are processed

Transaction categorisation runs on our servers in Canada, not on your device. To categorise a transaction, our systems read the merchant name, amount and date supplied by your bank.

Categorisation is deterministic and rule-based. We do not use machine learning models, and we do not send your transaction data to any third-party AI or inference provider.

Your data is never pooled with other customers' data, and it is never used to train anything that benefits another customer. Corrections you make improve categorisation within your own account only.

Bank connections

Bank connections are made through Plaid Inc. and Flinks Technology Inc. Your banking username and password are entered directly with Plaid or Flinks and are never transmitted to or stored by TrackE5.

Connections are read-only. TrackE5 cannot move money, initiate payments, or change anything at your bank.

Infrastructure

TrackE5 runs on Google Cloud Platform in northamerica-northeast1 (Montreal, Canada).

  • Network isolation — our database runs on a private IP inside a virtual private cloud. It is not reachable from the public internet.
  • Managed database — Cloud SQL for PostgreSQL, patched and maintained by Google.
  • Backups — automated daily backups with a seven-day retention window and point-in-time recovery. We test a restore from backup every quarter and record the result.
  • Logging — application and infrastructure logs are collected in Google Cloud Logging. Logs record operational telemetry only; no transaction content is written to them.

Access control

Multi-factor authentication is enforced on all staff cloud and source-control accounts. Access to production systems is granted on a least-privilege basis, and administrative activity is recorded in Google Cloud Audit Logs.

Access is removed promptly when someone leaves.

Secure development

  • Secrets management — credentials and API keys are held in Google Secret Manager and injected at runtime. They are never committed to source control.
  • Environment separation — development, staging and production run as separate, isolated environments.
  • Code review — changes are reviewed before deployment.

We have not yet commissioned an independent penetration test. We will say so here when that changes.

Incident response

We maintain a written incident response plan covering detection, containment, assessment and notification, and we review it at least annually.

If a breach creates a real risk of significant harm, we will notify affected users and the relevant regulators as required by PIPEDA, Quebec Law 25, and applicable US state breach-notification laws. We keep a record of every breach involving personal information for 24 months, whether or not it was reportable, as PIPEDA requires.

Reporting a vulnerability

If you believe you have found a security issue, email security@tracke5.com. We commit to acknowledging reports within three business days and will not pursue legal action against good-faith research that respects user privacy and avoids service degradation.

Compliance

TrackE5 does not currently hold SOC 2, ISO 27001 or PCI certification. We would rather tell you that plainly than imply a certification we do not have. If that changes, this page will say so and we will publish the report or certificate details.

We build against the requirements that apply to us — PIPEDA and Quebec Law 25 in Canada, and the FTC Safeguards Rule in the United States — and we describe our actual practices above rather than aspirational ones.

TrackE5

Automatic expense tracking, built for Canada and the US.

Product

  • Features
  • How It Works
  • FAQ
  • Pricing

Resources

  • About
  • Articles
  • Help Center
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Security
© 2026 TrackE5. Built in Canada.