Compliance

Last updated: 2026-09-13

GDPR

TracePoint complies with the General Data Protection Regulation. We process data lawfully, transparently, and for limited purposes. Data subjects have the right to access, rectify, erase, and port their data. Contact: privacy@secdh.com

CCPA

California Consumer Privacy Act compliance. California residents have the right to know what data is collected, request deletion, and opt out of data sale. We do not sell personal data. Contact: privacy@secdh.com

Audit trails

Every search, evidence view, and report export is logged in an immutable audit trail with user identity, timestamp, and IP address. Audit logs are retained for 7 years for legal compliance and subpoena response.

Data governance

All data is encrypted in transit (TLS 1.3) and at rest. Evidence is SHA-256 hashed. Access is role-based (owner/admin/analyst/viewer). Data retention is 90 days post-subscription, then permanent deletion.

Lawful use attestation

All users must attest to lawful purpose at signup. TracePoint is designed for licensed investigators, security professionals, and authorized analysts. Prohibited uses include stalking, harassment, and accessing private data.

Compliance · DataHound Security