Security is built into how TrackMe is delivered.
TrackMe for Splunk runs entirely inside your own environment. Your operational data never leaves your infrastructure or Splunk Cloud tenant — we are a software vendor, not a SaaS provider.
Last updated: June 2026
Security at a glance
The essentials reviewers and security teams ask about, in one place.
Self-hosted by design
Installed and run within your own Splunk Enterprise or Splunk Cloud. We do not host the product.
No customer data egress
Your operational data stays in your environment. We never store or access it.
MFA everywhere
Multi-factor authentication enforced across all company accounts and infrastructure.
Encryption
TLS 1.2+ in transit and AES-256 at rest across all systems and devices.
GDPR compliant
UK company; UK/EU GDPR aligned. DPA and SCCs available on request.
Cyber insured
Cyber liability and professional indemnity cover in place.
Deployment & data handling
This is the most important thing to understand about TrackMe's security posture.
- No multi-tenant platform: there is no shared environment where customer data could commingle.
- Your data residency is your own — TrackMe runs where your Splunk runs.
- Limited business contact data is held in the UK/EU and retained only for the duration of the relationship plus any legal period.
Application security & development
Every release is validated before it reaches Splunkbase or your environment.
- Source code in private GitHub repositories with branch protection and mandatory code review.
- Commit signing to verify code authorship and integrity.
- Automated CI/CD security checks and AI-assisted vulnerability scanning of the codebase.
- Continuous dependency monitoring via GitHub Dependabot.
- Mandatory Splunk AppInspect validation — Splunk's independent automated security and quality assessment — for every published release.
- Release integrity verified through checksums and digital signatures; distribution via official Splunkbase and our website only.
Infrastructure, access & encryption
Hosting
Company infrastructure runs on OVH Cloud (ISO 27001, SOC 1/2, HDS certified). Collaboration and email on Google Workspace (ISO 27001, SOC 2). Ubuntu-based servers with continuous automated security patching.
Access control
Least-privilege model; administrative access restricted and secured with MFA and SSH key-based authentication. Infrastructure access further restricted by source IP allowlisting.
Encryption
TLS 1.2 or higher in transit; AES-256 at rest. Full-disk encryption and automatic screen lock on all company devices.
Endpoint protection
Antivirus / endpoint protection deployed across devices, alongside built-in OS protection and automatic patching.
Monitoring & incident response
- TrackMe operates Splunk as its own SIEM for security monitoring; access and administrative actions are logged and retained for a minimum of six months.
- Documented Incident Response process: identify, contain, notify, remediate, review.
- Affected customers and authorities notified within 72 hours, in line with GDPR.
- Critical vulnerabilities targeted for patching within 48 hours, high-severity within 7 days.
AI features & governance
TrackMe's AI capabilities are optional and designed to keep you in control of your data.
- The AI Assistant is opt-in and disabled by default; it is governed by role-based access control.
- Provider-agnostic: you choose the AI provider (OpenAI, Azure OpenAI, Anthropic, Google Gemini, Mistral, Ollama, Splunk-hosted, or a custom/local endpoint) and use your own credentials.
- Local / self-hosted models are supported, enabling operation with zero external data transmission.
- Provider credentials are stored encrypted; optional data anonymisation is available.
- Your data is never used to train, retrain, or fine-tune any model.
- ML-based anomaly detection uses Splunk's MLTK and runs entirely within your environment.
Governed by our AI Usage & Governance Policy, available on request.
Business continuity
- Source code held in GitHub with full version history.
- Infrastructure reprovisionable from configuration-as-code.
- Geographically redundant backups; remote-capable operations.
- Reliance on highly resilient managed providers (GitHub, Google, OVH).
Compliance & certifications
We believe in being straightforward about what we hold today.
- GDPR (UK/EU): compliant. Data Processing Agreement and Standard Contractual Clauses available where applicable.
- SOC 2 / ISO 27001: not held by TrackMe Limited as a small, specialised vendor. We rely on independently certified infrastructure providers (OVH: ISO 27001, SOC 1/2; Google Workspace: ISO 27001, SOC 2) and validate every release via Splunk AppInspect.
- PCI-DSS / HIPAA: not applicable — no cardholder or health data is processed.
Documentation available on request
For vendor reviews and procurement, we can share the following under NDA where appropriate.
Security contact
To report a security concern or request security documentation, contact us atcontact@trackme-solutions.com.
© TrackMe Limited — Company No. 13817409, United Kingdom. This page summarises our security practices and does not form part of any contract.

