Compliance
Last updated: 2026-09-13
GDPR
TracePoint complies with the General Data Protection Regulation. We process data lawfully, transparently, and for limited purposes. Data subjects have the right to access, rectify, erase, and port their data. Contact: privacy@secdh.com
CCPA
California Consumer Privacy Act compliance. California residents have the right to know what data is collected, request deletion, and opt out of data sale. We do not sell personal data. Contact: privacy@secdh.com
Audit trails
Every search, evidence view, and report export is logged in an immutable audit trail with user identity, timestamp, and IP address. Audit logs are retained for 7 years for legal compliance and subpoena response.
Data governance
All data is encrypted in transit (TLS 1.3) and at rest. Evidence is SHA-256 hashed. Access is role-based (owner/admin/analyst/viewer). Data retention is 90 days post-subscription, then permanent deletion.
Lawful use attestation
All users must attest to lawful purpose at signup. TracePoint is designed for licensed investigators, security professionals, and authorized analysts. Prohibited uses include stalking, harassment, and accessing private data.