1. Security Overview
Security is foundational to Tracknesty. Our platform handles sensitive employee monitoring data β including screenshots, activity logs, and attendance records β and we treat that responsibility seriously. This page explains the technical and organisational measures we use to protect your data and keep the platform secure.
2. Data Architecture & Tenant Isolation
Tracknesty is a cloud SaaS platform designed with tenant data isolation and zero-vps disk exhaustion. β’ Customer workspaces operate within logically separated database partitions. β’ Large binary assets (screenshots, task files, discussion media) are encrypted and stored directly via Cloudflare R2 distributed object storage. β’ Real-time screen streaming utilizes peer-to-peer WebRTC connections with encrypted server relay fallback. β’ No customer server management or VPS maintenance is required.
3. Encryption Standards
All communication between the desktop agent, web dashboard, and API cluster is encrypted using TLS 1.3 / HTTPS. Unencrypted HTTP traffic is rejected. β’ Data at rest (database records and Cloudflare R2 media files) is encrypted using industry-standard AES-256 encryption. β’ Sensitive credentials, API keys, and signing tokens are stored in secured environment vaults β never hardcoded. β’ Screenshot files are private and served via temporary signed URLs with strict session authentication.
4. Authentication & Access Control
Tracknesty enforces secure session management with cryptographically signed, HttpOnly cookies. The platform provides 4 distinct role-based permission tiers: β’ Super Admin β global system management, tenant oversight, and seat licensing β’ Team Admin / Owner β workspace administration, billing, schedule policies, and full reports β’ Shared Admin / Manager β scoped permissions for assigned teams or departments β’ Member β individual employee account with self-service timesheets and attendance views Administrators can immediately revoke sessions and remove access for departing staff.
5. Desktop Agent Security
The Tracknesty desktop agent (Windows 10 & 11) is designed with transparency and safety in mind: β’ The agent operates visibly in the Windows system tray β it is never stealth or hidden spyware. β’ The agent communicates exclusively with official Tracknesty endpoints over encrypted TLS channels. β’ Anti-bypass tamper detection identifies mouse jigglers, auto-clickers, and unauthorized process suspensions. β’ Privacy safeguards: The agent does not record raw keystrokes, passwords, or personal webcam feeds.
6. Screenshot Handling & Privacy Blur
Screenshots are captured locally by the agent and uploaded to encrypted Cloudflare R2 storage over TLS 1.3. β’ Privacy Blurring: Configurable automatic blur filters protect sensitive data, passwords, and banking information. β’ Schedule Enforced: Tracking automatically stops outside designated working hours or during authorized breaks. β’ Self-Service Purge: Administrators can delete individual screenshots or bulk-purge records at any time.
7. Third-Party Sub-Processors
Tracknesty maintains a vetted, minimal set of enterprise sub-processors: β’ Lemon Squeezy β Merchant of Record and payment processing (PCI-DSS Level 1 certified). We never handle or store raw payment card data. β’ Cloudflare β R2 distributed edge storage, web application firewall (WAF), and global CDN. β’ Transactional Email Providers β Account verification, security alerts, and system notifications. All sub-processors are bound by strict Data Processing Agreements (DPAs).
8. Security Updates & Patching
We continuously monitor dependencies and system components for security advisories. Security patches and agent auto-updates are deployed seamlessly with zero downtime. Our information security management policies are actively aligned with ISO 27001 and SOC 2 Type II control frameworks.
9. Responsible Disclosure
If you discover a security vulnerability in Tracknesty, please report it responsibly: Email: support@tracknesty.com Subject: "Security Vulnerability Report" Please include: β’ A description of the vulnerability β’ Steps to reproduce β’ Potential impact We will acknowledge your report within 48 hours and aim to resolve critical issues within 7 days. We ask that you do not publicly disclose the vulnerability until a fix has been released.
10. Contact
For security questions, vulnerability reports, or penetration testing inquiries: Email: support@tracknesty.com Response time: within 48 hours for security reports