Skip to content
Security & Trust

Security is built into how TrackMe is delivered.

TrackMe for Splunk runs entirely inside your own environment. Your operational data never leaves your infrastructure or Splunk Cloud tenant — we are a software vendor, not a SaaS provider.

Last updated: June 2026

Security at a glance

The essentials reviewers and security teams ask about, in one place.

Self-hosted by design

Installed and run within your own Splunk Enterprise or Splunk Cloud. We do not host the product.

No customer data egress

Your operational data stays in your environment. We never store or access it.

MFA everywhere

Multi-factor authentication enforced across all company accounts and infrastructure.

Encryption

TLS 1.2+ in transit and AES-256 at rest across all systems and devices.

GDPR compliant

UK company; UK/EU GDPR aligned. DPA and SCCs available on request.

Cyber insured

Cyber liability and professional indemnity cover in place.

Deployment & data handling

This is the most important thing to understand about TrackMe's security posture.

TrackMe for Splunk is a self-hosted application. You install and operate it entirely on your own infrastructure (Splunk Enterprise) or within your Splunk Cloud tenant. TrackMe Limited does not host, store, access, or process your operational data. The only data we hold is very limited contact information — essentially names and email addresses — used solely for billing and support.
  • No multi-tenant platform: there is no shared environment where customer data could commingle.
  • Your data residency is your own — TrackMe runs where your Splunk runs.
  • Limited business contact data is held in the UK/EU and retained only for the duration of the relationship plus any legal period.

Application security & development

Every release is validated before it reaches Splunkbase or your environment.

  • Source code in private GitHub repositories with branch protection and mandatory code review.
  • Commit signing to verify code authorship and integrity.
  • Automated CI/CD security checks and AI-assisted vulnerability scanning of the codebase.
  • Continuous dependency monitoring via GitHub Dependabot.
  • Mandatory Splunk AppInspect validation — Splunk's independent automated security and quality assessment — for every published release.
  • Release integrity verified through checksums and digital signatures; distribution via official Splunkbase and our website only.

Infrastructure, access & encryption

Hosting

Company infrastructure runs on OVH Cloud (ISO 27001, SOC 1/2, HDS certified). Collaboration and email on Google Workspace (ISO 27001, SOC 2). Ubuntu-based servers with continuous automated security patching.

Access control

Least-privilege model; administrative access restricted and secured with MFA and SSH key-based authentication. Infrastructure access further restricted by source IP allowlisting.

Encryption

TLS 1.2 or higher in transit; AES-256 at rest. Full-disk encryption and automatic screen lock on all company devices.

Endpoint protection

Antivirus / endpoint protection deployed across devices, alongside built-in OS protection and automatic patching.

Monitoring & incident response

  • TrackMe operates Splunk as its own SIEM for security monitoring; access and administrative actions are logged and retained for a minimum of six months.
  • Documented Incident Response process: identify, contain, notify, remediate, review.
  • Affected customers and authorities notified within 72 hours, in line with GDPR.
  • Critical vulnerabilities targeted for patching within 48 hours, high-severity within 7 days.

AI features & governance

TrackMe's AI capabilities are optional and designed to keep you in control of your data.

  • The AI Assistant is opt-in and disabled by default; it is governed by role-based access control.
  • Provider-agnostic: you choose the AI provider (OpenAI, Azure OpenAI, Anthropic, Google Gemini, Mistral, Ollama, Splunk-hosted, or a custom/local endpoint) and use your own credentials.
  • Local / self-hosted models are supported, enabling operation with zero external data transmission.
  • Provider credentials are stored encrypted; optional data anonymisation is available.
  • Your data is never used to train, retrain, or fine-tune any model.
  • ML-based anomaly detection uses Splunk's MLTK and runs entirely within your environment.

Governed by our AI Usage & Governance Policy, available on request.

Business continuity

  • Source code held in GitHub with full version history.
  • Infrastructure reprovisionable from configuration-as-code.
  • Geographically redundant backups; remote-capable operations.
  • Reliance on highly resilient managed providers (GitHub, Google, OVH).

Compliance & certifications

We believe in being straightforward about what we hold today.

  • GDPR (UK/EU): compliant. Data Processing Agreement and Standard Contractual Clauses available where applicable.
  • SOC 2 / ISO 27001: not held by TrackMe Limited as a small, specialised vendor. We rely on independently certified infrastructure providers (OVH: ISO 27001, SOC 1/2; Google Workspace: ISO 27001, SOC 2) and validate every release via Splunk AppInspect.
  • PCI-DSS / HIPAA: not applicable — no cardholder or health data is processed.

Documentation available on request

For vendor reviews and procurement, we can share the following under NDA where appropriate.

IT Security PolicyAI Usage & Governance PolicyData Processing Agreement (DPA)Privacy PolicyInsurance summaryCompleted security questionnaire

Security contact

To report a security concern or request security documentation, contact us atcontact@trackme-solutions.com.

© TrackMe Limited — Company No. 13817409, United Kingdom. This page summarises our security practices and does not form part of any contract.