TraceSpec Security Statement
Effective date: 29 August 2026 Last updated: 31 August 2026
This Security Statement summarises how Elyven Ltd, trading as TraceSpec, approaches security for the TraceSpec platform.
It is intended to provide practical transparency for customers and prospective customers. It does not create a separate service level agreement, warranty or guarantee. Our legal obligations are set out in the Terms of Business, Privacy Policy and Data Processing Addendum.
1. Security approach
TraceSpec is a professional SaaS product used for heat tracing design decision support. We treat security, confidentiality and data integrity as important parts of the product.
Our security approach is based on:
- using reputable cloud infrastructure and SaaS providers;
- limiting access to customer data;
- maintaining appropriate account, application and infrastructure controls;
- protecting data in transit;
- maintaining backup and recovery processes;
- monitoring and responding to security issues;
- improving controls as TraceSpec scales.
2. Hosting and infrastructure
TraceSpec uses:
- Vercel for website/application hosting and deployment infrastructure;
- Supabase for database and related backend services;
- Clerk for sign-up, sign-in, authentication and session management;
- Stripe for subscription and payment processing;
- GitHub for source control and development workflow;
- no optional analytics or behavioural tracking technologies are enabled at launch;
- UK2.net / UK-2 Limited / THG for service/support email.
Core application database hosting is currently on Supabase Pro in AWS eu-central-1 / Frankfurt. Vercel is now on Pro and production functions are stated as pinned to Frankfurt (fra1), aligned with the Supabase region, subject to provider capabilities, performance, resilience and business requirements.
We maintain a Data Protection & Processing page with a subprocessor matrix and indicative processing locations.
3. Access control
We aim to restrict administrative access to systems and customer data to personnel and service providers who need access for legitimate business reasons, such as operating, supporting, securing, troubleshooting and improving TraceSpec.
Users are responsible for maintaining the confidentiality of their login credentials and ensuring that only authorised users have access to their account or workspace.
4. Authentication
TraceSpec uses authentication and session-management controls to restrict access to accounts and workspaces.
Customers should use strong, unique passwords and appropriate organisational security practices. Where additional authentication controls become available, customers are encouraged to use them.
5. Encryption
TraceSpec is designed to use HTTPS/TLS to protect data transmitted between users and the platform.
Data at rest is protected using the security controls of our hosting and database providers, where supported by those providers and configurations.
6. Customer project data
Customer project data entered into TraceSpec is treated as confidential customer information under our Terms of Business.
TraceSpec personnel may access customer project data where necessary to provide support, troubleshoot issues, maintain security, investigate misuse, improve the product, comply with law or enforce our terms.
We do not publish named customer project data or use it for identifiable case studies without appropriate permission.
7. Backups and resilience
TraceSpec maintains backup and recovery processes for operational resilience and disaster recovery.
Supabase Pro daily database backups are currently accessible for the last 7 days unless point-in-time recovery, a higher plan or another backup configuration is adopted. Backup retention may change over time for technical, cost, security, legal or resilience reasons.
Backups are not a customer archive service and are not a substitute for customers exporting or retaining their own reports and project records. Deleted data may remain in backups until the relevant backup cycle expires.
8. Monitoring and logging
We may use application, access, security and diagnostic logs to operate TraceSpec, troubleshoot issues, detect misuse, investigate incidents and maintain the integrity of the platform.
Logs are retained for a period appropriate to their purpose, unless needed for investigation, legal, security or compliance reasons.
9. Development and change management
TraceSpec is developed using controlled source-code and deployment workflows.
We may update the platform regularly, including calculation methods, scoring logic, product-library data, user interface, reports, dependencies, infrastructure and security controls.
Material product changes are managed in accordance with the Terms of Business.
10. Payments
Payments are processed by Stripe. TraceSpec does not store full payment card numbers on its own systems.
11. Incident response
If we become aware of a security incident affecting customer data, we will investigate and take appropriate steps to contain, mitigate and remediate the issue.
Where legally required, we will notify affected customers, users, regulators or other parties in accordance with applicable law and our Data Processing Addendum.
12. Customer responsibilities
Customers are responsible for:
- using TraceSpec only for authorised business/professional purposes;
- keeping credentials secure;
- managing user access and removing users who no longer need access;
- ensuring Customer Content is appropriate for a cloud SaaS platform;
- exporting and retaining reports or records they need;
- independently verifying TraceSpec outputs before use;
- promptly reporting suspected security issues.
13. Vulnerability reporting
If you believe you have discovered a security vulnerability in TraceSpec, please contact support@trace-spec.com with enough detail for us to investigate.
You must not perform intrusive security testing, scanning, exploitation, data access, data extraction or service disruption without our prior written consent.
14. Changes to this statement
We may update this Security Statement from time to time as TraceSpec, our infrastructure and our security controls evolve.
15. Contact
Security questions or reports: support@trace-spec.com Privacy questions: privacy@trace-spec.com