Skip to content

Security Policy

Effective Date:25th June 2026 
Last Update:25th June 2026 

 

 

 

 Overview

At Traphiclights security is fundamental to our mission of helping organizations manage, govern, and monitor AI systems across their business.

 

We understand that our customers entrust us with visibility into their AI environments, workflows, integrations, and operational data. Protecting that information is a core responsibility.

 

This Security Policy outlines the measures we take to safeguard customer information, protect platform integrity, and maintain the confidentiality, availability, and security of our services.

 

Our Security Principles

Our security program is built upon five core principles:

 

Security by Design

Security considerations are incorporated throughout product development, architecture design, and operational processes.

 

Least Privilege

Access to systems, data, and resources is restricted to only those individuals and services that require it.

 

Transparency

We strive to provide customers with clear information regarding our security practices and data handling procedures.

 

Continuous Improvement

We regularly review and improve our security controls to address emerging threats and evolving business requirements.

 

Customer Control

Customers retain ownership of their data and maintain control over how their AI environments are connected and governed.

 

 Data Protection

Data Ownership

Customers retain ownership of all customer data processed through the platform.

Customer data may include:

 

  • AI agent metadata
  • Configuration information
  • Audit logs
  • Usage information
  • Governance policies
  • Platform integration data
  • User account information

 

We do not claim ownership of customer data.

 

Data Encryption

 

Encryption in Transit

All communications between users, integrations, APIs, and platform services are encrypted using industry-standard Transport Layer Security (TLS).

 

Encryption at Rest

Customer data stored within our systems is encrypted using industry-standard encryption technologies.

 

This includes:

 

  • Databases
  • Backups
  • Audit records
  • Configuration data

 Access Control

Identity and Authentication

Access to customer environments is protected through authentication controls designed to prevent unauthorized access.

 

Supported controls may include:

 

  • Strong password requirements
  • Multi-factor authentication (MFA)
  • Single Sign-On (SSO)
  • Session management controls

 

Role-Based Access Control

The platform supports role-based access controls that enable organizations to manage permissions according to business requirements.

 

Examples include:

 

  • Administrators
  • Security teams
  • Compliance teams
  • Department managers
  • Standard users

 

Customers control user access within their environment.

 

Internal Access Controls

Access by TraphicLights personnel is restricted based on job responsibilities and business requirements.

Administrative access is limited to authorized personnel and is monitored and logged.

 

 Infrastructure Security

Secure Hosting

Platform infrastructure is hosted using reputable cloud infrastructure providers that maintain industry-recognized security standards.

 

Security measures include:

 

  • Network segmentation
  • Firewall protections
  • Infrastructure monitoring
  • Availability controls

Environment Separation

Production, testing, and development environments are logically separated to reduce risk and protect customer information.

 

Backup and Recovery

We maintain backup procedures designed to support business continuity and data recovery.

 

Backups are:

 

  • Protected against unauthorized access
  • Retained according to operational requirements
  • Regularly reviewed as part of recovery planning

 

 AI Governance Security

As an AI governance platform, TraphicLights is designed to provide organizations with visibility and control over AI activity.

 

Security features may include:

 

  • AI inventory management
  • Agent ownership tracking
  • Activity monitoring
  • Audit logging
  • Permission management
  • Governance reporting

 

These capabilities help customers improve accountability and oversight within their AI environments.

 

Monitoring and Logging 

We maintain monitoring capabilities designed to identify security events, operational issues, and unauthorized activity.

 

Monitoring may include:

 

  • Authentication events
  • Administrative actions
  • System access activity
  • API usage
  • Infrastructure health

 

Security-relevant activities are logged and retained in accordance with operational requirements.

 

 Vulnerability Management

We regularly review and improve platform security through:

 

  • Security assessments
  • Vulnerability monitoring
  • Dependency management
  • Software updates
  • Security patching

 

Critical security issues are prioritized for remediation based on risk and impact.

 

 Secure Development Practices

Security is integrated into our software development lifecycle.

 

Practices may include:

 

  • Code review processes
  • Dependency scanning
  • Security testing
  • Change management procedures
  • Access controls for source code repositories

 

 Incident Response

We maintain procedures for responding to security incidents.

 

Our incident response process includes:

 

Identification

Detection and assessment of potential security events.

 

Containment

Actions to limit impact and prevent further exposure.

 

Investigation

Analysis of affected systems and data.

 

Remediation

Corrective actions designed to address identified issues.

 

Communication

Notification of affected customers where required by law, contractual obligations, or applicable security commitments.

 

 

 

 Third-Party Services

Our platform may integrate with third-party services, including AI providers, cloud platforms, and business applications.

 

While we evaluate third-party providers carefully, customers acknowledge that third-party services operate under their own security practices and policies.

 

Customers are responsible for reviewing and approving third-party integrations used within their environment.

 

 

 

 Customer Responsibilities

Security is a shared responsibility.

 

Customers are responsible for:

 

  • Managing user permissions
  • Protecting account credentials
  • Enabling available security controls
  • Reviewing connected integrations
  • Maintaining compliance with applicable laws and regulations

 

Customers should promptly notify us of suspected security incidents involving their accounts.

 

 

 

Data Privacy

We are committed to protecting customer privacy.

 

Unless explicitly agreed otherwise:

 

  • Customer data is not sold.
  • Customer data is not shared with unrelated third parties.
  • Customer data is not used to train proprietary AI models.
  • Customer data remains under customer control.

 

Additional details are available in our Privacy Policy.

 

 

 

 Security Reporting

We encourage responsible reporting of security vulnerabilities.

 

Security concerns may be reported to:

 

Email: security@traphiclights.ai

 

Reports should include sufficient information to allow investigation and remediation.

 

 

 

 Continuous Improvement

Security threats continue to evolve, and so do our security practices.

 

We regularly review our policies, controls, and procedures to ensure we continue providing a secure platform that helps organizations govern AI safely and responsibly.

 

For questions regarding this Security Policy, please contact:

 

Email:security@traphiclights.ai