Traceway
Security & data

Where your data goes, and who else touches it

Written for the person doing the review, not for a brochure. Everything below is either something we have verified, something we are still confirming, or something we do not have yet — and each one says which.

Reviewed 7 August 2026
No gate.
No email capture.
No “contact sales”.
What the marks mean
✓ ConfirmedVerified against the running system.
◷ In progressBeing changed right now.
◌ To confirmWe believe it, and have not verified it against production. Shown, not hidden.
— Not yetNot the case today.
01

Where it is held

Your data is held in the region you choose. We provision your workspace’s database in that region, and its records, files and backups all stay there.

✓ Confirmed
You choose the region your data is held in.
Agreed with you when your workspace is set up, and provisioned for you rather than picked from a menu. If your requirement is that your data never leaves a particular region, say which and that is where it goes.
✓ Confirmed
A workspace’s records, files and backups all stay in its own region.
Backups are not a second location to worry about — a backup never leaves the region its workspace is in. We state regions only, never a datacentre or an address.
✓ Confirmed
Customers are kept apart from one another, whichever region they are in.
Access rules are enforced on every single query, and a workspace in its own region is in its own database as well.
Every place your data sits
What
What is in it
Kept for
State
Records
Every decision, strategy, comment, membership record and audit event in your workspace — in your region.
No scheduled deletion
✓ Confirmed
Files
Attachments and images you upload, exactly as you sent them — in your region.
No scheduled deletion
✓ Confirmed
Search
Search runs inside the same database, in the same region. There is no separate search service and no third-party search vendor — so searching your workspace sends nothing anywhere.
With the records
✓ Confirmed
Audit log
The record of who did what. Held in the same database as your records, in the same region. The only thing here with a retention setting — see band 05.
See band 05
✓ Confirmed
Backups
Daily backups, kept 7 days, on the production plan a customer workspace runs on. We are being exact rather than flattering here: the plan that provides them is switched on before any customer data is held, so this is a commitment about your workspace and not a description of our pre-launch environment.
7 days
◷ In progress
Operational logs
Logs produced by the hosting provider while the application runs.
window
◌ To confirm
Staff access
When our team needs to look at your workspace to help, they enter it read-only, for a fixed 30 minutes, and only after typing a reason. The person, the reason and the time bounds are written to a trail that cannot be edited, and the session can be ended on the spot. What we do not have yet is your approval being asked for first — the access is recorded and bounded, not consented to in advance.
Session-scoped
✓ Confirmed
02

Who else touches it

Two lists, deliberately kept apart. The first is the one you came for: companies that can hold or see data inside a customer workspace. The second covers the website and our sales process, and touches no workspace at all.

The product — companies that can hold or see your workspace data
Company
What they do
What reaches them
State
The database and file storage behind your records, your audit log and every file you upload.
Everything, including decision content.
✓ Confirmed
Sign-in, sessions, organisation membership and invitations.
Names, email addresses and sign-in events. No record content. Where you use your own single sign-on, no password of yours ever reaches them.
✓ Confirmed
Powers Trace — drafting, extraction, search and answers.
The content of one request at a time. See band 03.
✓ Confirmed
Runs the application, and reports page views and page performance.
Page addresses — which can include a record’s identifier — device type and approximate location. No record content.
✓ Confirmed
✓ Confirmed
All four have a data-processing agreement in force, covering both EU and UK transfers.
Each one incorporates its agreement automatically through its terms, and each carries a UK addendum — so the transfer mechanism exists in both regimes without a separate signature. Checked against each provider’s own published terms on 1 August 2026.

Two absences worth stating, because a reviewer will look for them and their absence is otherwise ambiguous: there is no third-party error-monitoring vendor and no separate transactional email vendor — account and invitation email goes through the identity provider above.

Integrations you connect yourself — a work tracker, a document store — are not our sub-processors. They are your own vendors, and data moves to them because you chose to connect them.

The website — traceway.com, the waitlist and demo calls

HubSpot, Google Analytics, Zoom, Fathom and Google Workspace support the website and our sales conversations, all processing in the United States. None of them touches a customer workspace. They are listed in full in our privacy policy.

03

The AI question

For a product with an AI assistant this is the first thing anyone asks, so it gets the most space and the most sourcing.

✓ Confirmed
Anthropic may not train models on your content — and neither do we.
Trace runs on Anthropic, whose Commercial Terms state that Anthropic may not train models on Customer Content, defined as the inputs submitted and the outputs returned. It is a published term you can read yourself rather than take from us — their statement ↗.
✓ Confirmed
Traceway trains nothing either.
No shared corpus across customers, no “learn from your workspace” setting, and no path by which your records improve anything we ship.
✓ Confirmed
Your records go to the model only for the request that needs them.
A question you ask, a document you paste, an image you upload. There is no background job that ships your existing records anywhere, and no bulk upload of your workspace.
✓ Confirmed
Rating a Trace answer sends nothing to the model provider.
This matters more than it sounds. The no-training term carves out content a customer explicitly submits as feedback — which makes a thumbs-up button a training pipeline unless it is deliberately built not to be. Ours records the rating and which answer it refers to, in your own workspace, and stops there.
✓ Confirmed
Filing a bug report does send its text to the model.
When you report a problem, the text of your report is sent to the model to structure it into a reproducible ticket. We would rather say so here than have it found.
◷ In progress
Trace answering strictly within your visibility rules.
Trace’s chat and search apply your workspace’s visibility rules before assembling an answer. We have found one remaining screen that assembles its summary without that filter, and it is being closed. Until that work is finished we will not claim this as complete — which is exactly the kind of thing this page exists to say out loud.
— Not yet
Choosing your own model vendor, or using your own model deployment.
Not available today.
On how long the model provider keeps a request: that is their fact, published in their own documentation, and we point you there rather than paraphrase it. We draw the distinction deliberately — “not trained on” and “not stored” are different sentences, and we have not arranged the second.
04

What the audit trail proves

Every governance product claims an audit trail. Almost none of them say what it cannot establish — and a reviewer who finds a limit we did not mention discounts everything we did. So the right-hand column is published on purpose.

It proves
Who acted, and when — actor, action and timestamp for every governance event.
The sequence in which a record was drafted, reviewed, approved, superseded or revisited.
What the record said at the time: an approval points at the version that was approved, not the current one.
That a sealed export has not been altered since it was produced.
It does not prove
That the approver read it. It records that an account with approval authority clicked approve. Attention is not observable.
That the named human was at the keyboard. It proves an authenticated session — a shared credential or an unlocked laptop is outside what any log can see.
That the decision was right. It is a record of process, never of judgement.
That nothing happened elsewhere. A decision made in a corridor and never captured leaves no trace here.
That a linked system did what it said. A ticket referenced by a decision is evidence about that tracker, held by that tracker.
✓ Confirmed
Audit rows are chained to their predecessor, so a deletion inside the trail is detectable.
Chaining has been in place since 27 June 2026 and covers every event created from that date onward. Events recorded before it are sealed at export but not chained — a reviewer who assumed the entire history was chained would have been misled by omission, so the boundary is stated rather than the headline.
— Not yet
Third-party notarisation, or a public transparency log.
Not today.
✓ Confirmed
There is no way to edit or delete an audit event in the product.
Not for an admin, not for a workspace owner, and not through any screen we operate. Band 01 is honest that some Traceway staff hold administrative access to the database itself; what we are claiming here is that no product path exists, not that the underlying store is beyond human reach. Anyone claiming the stronger version has not thought about their own database administrators.
05

How data leaves

Reviewers ask how data gets out because they are really asking whether they can leave.

✓ Confirmed
Any workspace admin can export the whole workspace, at any time, without asking us.
Decisions, strategies, comments, files, members and audit events.
◌ To confirm
Your audit-log retention window is a setting you control.
One, three or seven years, or keep everything. Seven years is the default.
— Not yet
Old audit events being deleted automatically when they pass that window.
The setting exists and is yours to choose, but nothing enforces it yet — today we keep audit events until you ask us to remove them. Deleting audit history permanently is high-stakes and we would rather build it carefully than early. This is the single thing on this page most likely to be assumed rather than checked, so it is stated plainly.
— Not yet
Erasing one person from a workspace on your own.
Removing a member revokes their access today. Erasing what is held about them is a request to us, not yet a button you press. When it does ship, the governance record of what someone decided or approved is deliberately kept — you cannot un-sign a contract by asking to be forgotten, and a decision record whose approver can vanish proves nothing.
◌ To confirm
Closing your account returns your data before it is deleted.
Handled by our team on request rather than as a self-serve button, and we would rather say that than imply otherwise.

Your decisions and files are never on a deletion clock. The retention setting above governs the audit log — the record of events — and nothing else.

06

Notice of change

✓ Confirmed
30 days’ notice before a new company handles your data.
By email to every workspace administrator, with a route to object. Every addition, removal and replacement will be listed here with its date.

What we do not publish, and why. Software versions, hostnames, internal architecture and the security tooling we run stay off this page — they answer no question a reviewer actually has, and they tell someone where to knock. Anything a reviewer genuinely needs that is not here — a completed security questionnaire, or a current statement of what we do and do not yet have — we give on request.

Something here unmarked, or a question this page does not answer?
Ask us at security@traceway.com and you will get the current position in writing, including where the answer is “not yet”. If you believe you have found a vulnerability, that is the same address and we will confirm receipt.
Last reviewed 7 August 2026. Every claim on this page carries its state.
Anything unmarked, ask — we would rather answer than have you assume.