Security
What the product actually does.
This page lists controls that are in the TraceHawk codebase today. It is not a certification, and it does not describe an audit we have not had.
Sign-in
- Passwords are stored hashed.
- The workspace opens after the email address is confirmed.
- A new browser is asked for a one-time code by email. You can turn on an authenticator app instead. The authenticator secret and recovery codes are encrypted.
- Sign-in, registration, password reset, and the ingest endpoint are rate limited.
Project keys
- The browser key is public in the page source. You can limit which origins may send, rotate the key, or set an expiry. The full key is shown once.
- The PHP key belongs in TRACEHAWK_DSN, not in source.
Events and integrations
- Ingest drops request headers whose names look like a cookie, authorization value, token, password, or secret.
- Local variables whose names look like a password, secret, token, credential, or API key are stored as [Filtered].
- A Jira API token or Slack webhook URL you save is encrypted before it is stored.
Billing and transport
Checkout is handled by Paddle. TraceHawk does not ask for or store a card number. The public site and the documented ingest URL use HTTPS at https://tracehawk.net.
What this is not
TraceHawk does not claim SOC 2, ISO 27001, or a GDPR certification. Project keys are not hashed. There is no published penetration test. Questions go to support@tracehawk.net.