Defence-in-depth, audited annually.
An honest account of how we protect your data — what we do, what we audit, and what we worry about.
How we approach defence-in-depth.
What we publish.
Annual report
Audited by Coalfire. Available on request to customers and prospects under NDA. Updated April 2026.
Certification
Issued by BSI, recertified annually. Covers all Tracket systems and offices.
Penetration test summary
Q1 2026 full-stack pentest by KPMG. No critical or high-severity findings. Summary report available on request.
Public programme
880 valid reports paid out since 2020. Median triage time 14h. Hall of fame at security.html#bounty.
Data Processing Agreement
GDPR-compliant DPA available to all paying customers. Counter-signed copies auto-generated when you upgrade to Standard or above.
Business Associate Agreement
Available on Enterprise. Includes ePHI segregation, audit-log access, and customer-managed key requirements.
Found a vulnerability?
We pay for valid security reports. 24-hour triage SLA. Hall of fame for first-finders.