Trust & Security
Our approach
Traken is a deterministic FinOps engine built for security and data minimisation from the ground up. This page summarises our security posture honestly — including both what we have and what we do not yet have.
Zero-Data architecture
Traken never ingests, transmits, or stores the content of your AI prompts or the AI providers' responses. We process only token counters, cryptographic hashes, numeric cost/usage figures, and business metadata. This dramatically reduces the sensitivity of the data we handle.
EU data residency
Our default infrastructure runs in the European Union. Application hosting is with Hetzner (Germany); our database and authentication run on Supabase (EU region); default narrative generation uses Mistral AI (EU). See our Subprocessors page for the full list and transfer mechanisms.
Encryption
Data is encrypted in transit using TLS and at rest on our infrastructure.
Inherited infrastructure certifications
We build on providers with recognised, independently verified certifications. These certifications apply to those providers' own services, not to Traken:
- Hetzner Online GmbH holds ISO/IEC 27001:2022 (awarded by SOCOTEC Certification, covering the Nuremberg, Falkenstein, and Helsinki data centres) and, for its cloud services, a BSI C5:2020 Type 2 attestation.
- Cloudflare, Inc. maintains SOC 2 and is certified under the EU-U.S. Data Privacy Framework (Active; also Swiss-U.S. DPF and UK Extension), as listed on the U.S. Department of Commerce Data Privacy Framework List (participant 5666).
- Supabase is SOC 2 Type 2 and ISO/IEC 27001:2022 certified.
What Traken does not yet hold
Traken itself does not currently hold SOC 2 or ISO 27001 certification. We do not claim any certification we do not have. We will update this page if that changes.
Reports are for internal management use only
Traken's reports — including the Verified Report — are for the customer's internal management use. They are not an audit, attestation, assurance engagement, or professional advice, and no third party may rely on them. See the Verified Report terms for the full non-reliance notice.
Reporting a vulnerability
See our Vulnerability Disclosure Policy and /.well-known/security.txt, or email security@traken.ai.