TRAKEN

Trust & Security

Last updated: 19 July 2026

Our approach

Traken is a deterministic FinOps engine built for security and data minimisation from the ground up. This page summarises our security posture honestly — including both what we have and what we do not yet have.

Zero-Data architecture

Traken never ingests, transmits, or stores the content of your AI prompts or the AI providers' responses. We process only token counters, cryptographic hashes, numeric cost/usage figures, and business metadata. This dramatically reduces the sensitivity of the data we handle.

EU data residency

Our default infrastructure runs in the European Union. Application hosting is with Hetzner (Germany); our database and authentication run on Supabase (EU region); default narrative generation uses Mistral AI (EU). See our Subprocessors page for the full list and transfer mechanisms.

Encryption

Data is encrypted in transit using TLS and at rest on our infrastructure.

Inherited infrastructure certifications

We build on providers with recognised, independently verified certifications. These certifications apply to those providers' own services, not to Traken:

What Traken does not yet hold

Traken itself does not currently hold SOC 2 or ISO 27001 certification. We do not claim any certification we do not have. We will update this page if that changes.

Reports are for internal management use only

Traken's reports — including the Verified Report — are for the customer's internal management use. They are not an audit, attestation, assurance engagement, or professional advice, and no third party may rely on them. See the Verified Report terms for the full non-reliance notice.

Reporting a vulnerability

See our Vulnerability Disclosure Policy and /.well-known/security.txt, or email security@traken.ai.