DRAFT — pending review. This page describes our current security approach for launch readiness and will be expanded as formal certifications and policies are completed. It is not a contractual commitment.
Trust
Security at GaugeTrace
GaugeTrace handles field evidence that teams rely on — readings, locations, technician identity, and supporting documents. We design the platform to keep that data protected and access controlled.
Invite-only, SSO authentication
Access is provisioned by invitation. Users sign in with Google, Microsoft, or company SSO — there is no open self-serve signup.
Encryption in transit
Traffic between clients and the platform is encrypted using TLS. Evidence files are stored in managed object storage.
Least-privilege access
Company membership and roles scope what each user can see and do. Production access is limited and audited.
Trusted infrastructure
Authentication, database, and evidence storage run on Supabase, with identity verification via Google and Microsoft.
Data handling
How we collect, use, retain, and share personal data — including customer field data, SSO identity, and marketing leads — is described in our Privacy Policy. Our sub-processors are listed there and available on request.
Reporting a vulnerability
If you believe you have found a security issue, please contact security@gaugetrace.com. We welcome responsible disclosure and will work with you to investigate and resolve valid reports.