CAD REGISTER // SECURITY & DATA INTEGRITY // OVERVIEW

Built for commercially sensitive purchasing data.

Supplier quotes contain proprietary pricing, margin structures, and confidential catalog terms. Traceline is architected so that your commercial data remains isolated, ephemeral in model memory, and under your complete control.

ISOLATION // DATABASE KERNEL RLS
AI MEMORY // ZERO MODEL TRAINING (ZDR)
ACCESS // TIME-BOXED OPERATOR GRANTS
LIFECYCLE // IRREVOCABLE HARD DELETION
PILLAR 01 // DATA ISOLATION

Kernel-Level Tenant Isolation

Multi-tenant PostgreSQL Row-Level Security (RLS) strictly enforced at the database kernel, preventing cross-organization leakage before application queries return.

Kernel-Level Enforcement

Every database table partitions data by organization_id. Tenant isolation is enforced natively by PostgreSQL's Row-Level Security engine on the active session role (app.current_org), not by application-level software logic or ORM filter conventions.

No Bypass Role

The application connects using a dedicated non-superuser role (traceline_app) that explicitly lacks BYPASSRLS privileges. Even in the theoretical event of an application logic bug, cross-tenant data access is blocked directly by the database engine.

Continuous Automated Verification

Structural automated test suites execute in CI against isolated PostgreSQL test fixtures to verify RLS policies on every commit, ensuring no tenant leaks can ever be merged.

EXHIBIT // POSTGRESQL RLS ENFORCEMENT DATABASE KERNEL · ROLE: TRACELINE_APP
-- 1. Enforce strict RLS on all tenant tables
ALTER TABLE comparisons ENABLE ROW LEVEL SECURITY;
ALTER TABLE comparisons FORCE ROW LEVEL SECURITY;
-- 2. Restrict row access to session organization
CREATE POLICY tenant_isolation_policy
ON comparisons
AS RESTRICTIVE
USING (
organization_id = NULLIF(
current_setting('app.current_org', true),
''
)::uuid
);
-- 3. Production connection role without bypass
CREATE ROLE traceline_app
WITH LOGIN NOBYPASSRLS;
PILLAR 02 // MODEL INTEGRITY

AI Privacy & Zero Model Training

Stateless document parsing with cryptographically enforced Zero Data Retention (ZDR). Frontier models interpret document geometry; deterministic software calculates all totals.

NEGATIVE GUARANTEE // STRICT COMMITMENT

Your commercial quotes are never used for AI training.

No customer pricing data, supplier line items, vendor terms, or document fragments are retained to train, fine-tune, or adapt foundation models—neither by Traceline nor by third-party model providers.

Stateless Extraction Only

Frontier large language models (LLMs) are used solely for initial document parsing and schema extraction. All numerical calculations, unit conversions, pack multiplier normalizations, and bid tab totals are handled deterministically by audited Python and spreadsheet algorithms.

Zero Data Retention Flags

Every API payload dispatched to model providers explicitly sets data_collection: "deny" and zdr: true. Provider-side logging, caching, and evaluation retention are programmatically blocked.

Ephemeral Inference Memory

Prompts and quote excerpts exist in model inference memory only for the duration of the HTTP request. They are ephemeral in transit, never written to model provider persistent disks, never logged in vendor debugging caches, and never accessible to other customers.

EXHIBIT // STATELESS INFERENCE PAYLOAD ENFORCING ZDR: TRUE
// Production inference payload header & body
{
"model": "anthropic/claude-3-5-sonnet",
"data_collection": "deny",
"zdr": true,
"store": false,
"messages": [
{
"role": "user",
"content": "[EPHEMERAL_QUOTE_TEXT_STREAM]"
}
]
}
PILLAR 03 // DATA LIFECYCLE

Access Governance & Irrevocable Hard Deletion

Customer-governed data lifecycle. Engineering and support staff hold zero permanent access to quotes, and deletions irrevocably wipe database rows and object storage files.

Operator Access Grants

Traceline support and engineering personnel have zero default access to customer quote files or comparison tables. Support debugging requires an Operator Access Grant explicitly authorized by an organization administrator, bounded to a strict, time-limited window, and revocable at any moment. All operator actions are immutably logged to an append-only audit trail.

Customer-Controlled Retention

Documents and comparison history remain in your organization for as long as your procurement audit cycles require. Traceline does not silently purge historical records or auto-expire quote comparisons unless instructed by your team.

Irrevocable Hard Deletion

When an organization owner deletes a Comparison, Project, or Organization, Traceline executes an immediate hard deletion across both database rows and underlying object storage. Audit activity logs preserve solely timestamps and actor user IDs; all commercial contents, line items, supplier identities, and files are permanently purged.

EXHIBIT // LIFECYCLE & DELETION CONTRACT APPEND-ONLY AUDIT · INSTANT PURGE
-- Operator Access Grant: time-boxed SQL check
SELECT grant_id FROM operator_access_grants
WHERE organization_id = $1
AND operator_id = $2
AND status = 'ACTIVE'
AND expires_at > clock_timestamp();
-- Irrevocable Hard Deletion: SQL + Storage Wipe
BEGIN TRANSACTION;
DELETE FROM comparisons
WHERE id = $target_comparison_id;
-- Cascades: quote_items, match_lines, revisions
purge_storage_prefix(
bucket := 'quotes',
prefix := $organization_id || '/' || $target_id
);
COMMIT;
PILLAR 04 // OBSERVABILITY

Telemetry & Scrubbing

System observability designed to prevent customer data leakage. Error reports are sanitized before transit, and analytics operate without tracking cookies or device fingerprints.

Payload Scrubbing

Application error monitoring via Sentry is configured with aggressive data scrubbing filters. HTTP request bodies, local stack variables, commercial line item amounts, file contents, and user identities are scrubbed directly on the application host before error reports leave the cluster.

100% Cookieless Analytics

Public marketing analytics via Plausible operate with daily rotating cryptographic salt hashes, storing zero cookies, zero localStorage keys, and zero persistent cross-site device fingerprints. Web traffic is measured without invasive buyer surveillance.

EXHIBIT // TELEMETRY SANITIZATION SENTRY FILTER · COOKIELESS PLAUSIBLE
// In-cluster telemetry scrubbing contract
sentry_config: {
strip_request_bodies: true,
strip_local_variables: true,
pii_sanitization_rules: [
"regex:pricing_lines",
"regex:supplier_credentials",
"regex:quote_document_buffers"
]
}
// Plausible cookieless privacy spec
plausible_config: {
cookies_enabled: false,
local_storage: false,
fingerprinting: false,
session_hash: "daily_rotating_salt"
}
05 // TRANSPARENCY REGISTER

Public Subprocessor Register

We maintain a transparent record of all third-party cloud infrastructure and specialized subprocessors involved in hosting, authenticating, and running Traceline.

Entity Purpose Data Handled Data Location / Safeguards
Microsoft Azure Core Cloud Infrastructure, Compute, PostgreSQL Flexible Server, Blob Storage Encrypted database records, stored supplier PDF/XLSX/CSV quotes United States / Canada (Azure Tenant)
WorkOS Authentication & Session Management User email, name, organization membership (Passwords are never stored by Traceline) United States (SOC 2 Type II certified)
Anthropic / OpenRouter Stateless Document Extraction & Translation Ephemeral quote text fragments for extraction United States (Zero Data Retention enforced; data_collection: deny)
Plausible Analytics Cookieless Web Traffic Analytics Anonymous pageviews, daily rotating salt hash (No cookies, no PII) European Union (Hetzner, Germany; GDPR compliant)
Sentry (Functional Software, Inc.) Application Error Tracking Scrubbed error traces (Request bodies and commercial quote PII stripped) United States (SOC 2 Type II certified)
REGISTER REV // 2026.10 CHANGE NOTIFICATION: 30 DAYS ADVANCE NOTICE
ENTERPRISE SECURITY // DIRECT INQUIRY

Evaluating Traceline for your procurement organization?

We understand the compliance requirements of mid-market and enterprise procurement teams. We regularly complete customer vendor security questionnaires and provide custom Data Processing Agreements (DPAs).

Traceline operates on verifiable engineering constraints, strict database row-level security, and stateless AI extraction rather than cosmetic marketing badges. If your legal, infoSec, or procurement review team needs architecture reviews, security questionnaire answers, or custom DPAs, our team is ready to assist.

TYPICAL RESPONSE TIME // < 1 BUSINESS DAY

Bring one real RFQ. See what it catches.

Test Traceline on an upcoming comparison. Experience pack normalization, common scope calculation, and provenance tracing on your own documents.