Encryption
Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256.
Encryption keys are managed by Google Cloud Platform on our behalf. TrackE5 is not end-to-end encrypted and is not a zero-knowledge service. Our systems process your transaction data in order to categorise it and produce your budgets and reports. We describe exactly how below, and in our Privacy Policy.
How your transactions are processed
Transaction categorisation runs on our servers in Canada, not on your device. To categorise a transaction, our systems read the merchant name, amount and date supplied by your bank.
Categorisation is deterministic and rule-based. We do not use machine learning models, and we do not send your transaction data to any third-party AI or inference provider.
Your data is never pooled with other customers' data, and it is never used to train anything that benefits another customer. Corrections you make improve categorisation within your own account only.
Bank connections
Bank connections are made through Plaid Inc. and Flinks Technology Inc. Your banking username and password are entered directly with Plaid or Flinks and are never transmitted to or stored by TrackE5.
Connections are read-only. TrackE5 cannot move money, initiate payments, or change anything at your bank.
Infrastructure
TrackE5 runs on Google Cloud Platform in northamerica-northeast1 (Montreal, Canada).
- Network isolation — our database runs on a private IP inside a virtual private cloud. It is not reachable from the public internet.
- Managed database — Cloud SQL for PostgreSQL, patched and maintained by Google.
- Backups — automated daily backups with a seven-day retention window and point-in-time recovery. We test a restore from backup every quarter and record the result.
- Logging — application and infrastructure logs are collected in Google Cloud Logging. Logs record operational telemetry only; no transaction content is written to them.
Access control
Multi-factor authentication is enforced on all staff cloud and source-control accounts. Access to production systems is granted on a least-privilege basis, and administrative activity is recorded in Google Cloud Audit Logs.
Access is removed promptly when someone leaves.
Secure development
- Secrets management — credentials and API keys are held in Google Secret Manager and injected at runtime. They are never committed to source control.
- Environment separation — development, staging and production run as separate, isolated environments.
- Code review — changes are reviewed before deployment.
We have not yet commissioned an independent penetration test. We will say so here when that changes.
Incident response
We maintain a written incident response plan covering detection, containment, assessment and notification, and we review it at least annually.
If a breach creates a real risk of significant harm, we will notify affected users and the relevant regulators as required by PIPEDA, Quebec Law 25, and applicable US state breach-notification laws. We keep a record of every breach involving personal information for 24 months, whether or not it was reportable, as PIPEDA requires.
Reporting a vulnerability
If you believe you have found a security issue, email security@tracke5.com. We commit to acknowledging reports within three business days and will not pursue legal action against good-faith research that respects user privacy and avoids service degradation.
Compliance
TrackE5 does not currently hold SOC 2, ISO 27001 or PCI certification. We would rather tell you that plainly than imply a certification we do not have. If that changes, this page will say so and we will publish the report or certificate details.
We build against the requirements that apply to us — PIPEDA and Quebec Law 25 in Canada, and the FTC Safeguards Rule in the United States — and we describe our actual practices above rather than aspirational ones.