Security & Trust

Your billing data, kept to itself

Track & Bill holds the money side of your consulting business — clients, rates, invoices. Here is exactly how it is protected, in plain language. We state only what is true of the product today, and we do not claim a certification we do not hold.

Last updated 19 August 2026

Every company’s data is isolated at the database

Each company (“tenant”) is separated inside the database by row-level security — rules enforced by PostgreSQL itself, not just by the app. A query can only ever return rows for a company you are a verified member of; the separation does not depend on the interface behaving correctly.

This is adversarially tested: we run attack simulations that attempt cross-company reads and writes, member self-promotion, and manager-permission abuse. As of the 19 August 2026 review, every one was blocked.

Encrypted in transit and at rest

All traffic runs over HTTPS/TLS. Data at rest is encrypted by our database and storage provider (Supabase, on AWS). We never store your password — authentication is handled by our provider and passwords are kept only as salted hashes.

We never touch card numbers

Your subscription is billed through Stripe; your clients pay your invoices through your own Stripe account. Card data is handled by Stripe (a PCI-DSS Level 1 provider) — Track & Bill never sees, stores, or processes card numbers, yours or your clients’.

Least-privilege access, MFA on admin systems

Administrative access to the systems that run Track & Bill is limited to the operator and protected by multi-factor authentication. Application secrets (API keys, tokens) live in server-side secret stores, never in the app you download or in our code.

Your data is yours — export or delete it anytime

You can export everything you have entered — clients, time, mileage, expenses, invoices, the retainer ledger — with one click, on every plan, at any time, including during the trial and after you cancel. Account deletion is available in the app with a typed confirmation and removes your data from the live system.

If we ever shut Track & Bill down, you get at least 90 days’ notice and your full export before anything is removed.

Changes are tested before they ship

Code changes are written with their tests, run through an automated test suite that must pass, and deployed to a preview build for verification before they reach production. We keep a running change log, and code changes are reviewed on a weekly cadence.

Monitoring and backups

The platform is health-checked continuously and errors are logged for review. The database is backed up by our provider with point-in-time recovery, so data can be restored if something goes wrong.

Who we rely on (subprocessors)

The infrastructure under Track & Bill. Each of these runs its own audited security program.

ProviderWhat it doesTheir attestation
Supabase (on AWS, US)Database, authentication, file storage, serverless functionsSOC 2 Type II
NetlifyWebsite and app hosting / content deliverySOC 2 Type II
StripeSubscription billing and invoice paymentsSOC 2 + PCI-DSS Level 1
ResendTransactional email (invoices, account email)SOC 2 Type II

Provider attestations are the providers’ own; verify current status on their trust pages. This list changes only when our infrastructure does.

Security FAQ

Is Track & Bill SOC 2 certified?

Not today, and we won’t claim to be until it’s true. SOC 2 is a formal audit of an organization by a licensed CPA firm. We have built the product to the technical bar a SOC 2 Security review tests — tenant isolation, encryption, access control, tested change management — and we keep the evidence and written policies behind it. If you need a formal report for a procurement process, contact us and we’ll talk about timing.

Can another company using Track & Bill see my data?

No. Data is isolated per company at the database level by row-level security, and that isolation is adversarially tested. Even a consultant who works for several companies on the platform only ever sees the companies they are a verified member of — never a third one, and never one company’s data while working in another.

Where is my data stored?

In a PostgreSQL database hosted by Supabase in the United States (AWS us-west-2), encrypted at rest, with point-in-time backups.

Do you sell or share my data?

No. Your business records exist only to run the product for you. We do not sell your data and do not use it to build advertising profiles. Our subprocessors are listed on this page.

How do you handle a security issue if one is found?

We investigate on report, fix with a tested change, and — where a fix affects customer data or availability — notify affected account owners. You can report a suspected issue to the email below.

Can I get your security policies?

Yes. Our information-security, access-control, change-management, incident-response, data-retention, vendor-management, and business-continuity policies are available to customers and prospects on request — email us.

Report a security concern

Found something, or need our security documentation for a procurement review? Email skrubinski@tuninglabs.net — a human reads it.