Security Policy
Overview
At Traphiclights security is fundamental to our mission of helping organizations manage, govern, and monitor AI systems across their business.
We understand that our customers entrust us with visibility into their AI environments, workflows, integrations, and operational data. Protecting that information is a core responsibility.
This Security Policy outlines the measures we take to safeguard customer information, protect platform integrity, and maintain the confidentiality, availability, and security of our services.
Our Security Principles
Our security program is built upon five core principles:
Security by Design
Security considerations are incorporated throughout product development, architecture design, and operational processes.
Least Privilege
Access to systems, data, and resources is restricted to only those individuals and services that require it.
Transparency
We strive to provide customers with clear information regarding our security practices and data handling procedures.
Continuous Improvement
We regularly review and improve our security controls to address emerging threats and evolving business requirements.
Customer Control
Customers retain ownership of their data and maintain control over how their AI environments are connected and governed.
Data Protection
Data Ownership
Customers retain ownership of all customer data processed through the platform.
Customer data may include:
- AI agent metadata
- Configuration information
- Audit logs
- Usage information
- Governance policies
- Platform integration data
- User account information
We do not claim ownership of customer data.
Data Encryption
Encryption in Transit
All communications between users, integrations, APIs, and platform services are encrypted using industry-standard Transport Layer Security (TLS).
Encryption at Rest
Customer data stored within our systems is encrypted using industry-standard encryption technologies.
This includes:
- Databases
- Backups
- Audit records
- Configuration data
Access Control
Identity and Authentication
Access to customer environments is protected through authentication controls designed to prevent unauthorized access.
Supported controls may include:
- Strong password requirements
- Multi-factor authentication (MFA)
- Single Sign-On (SSO)
- Session management controls
Role-Based Access Control
The platform supports role-based access controls that enable organizations to manage permissions according to business requirements.
Examples include:
- Administrators
- Security teams
- Compliance teams
- Department managers
- Standard users
Customers control user access within their environment.
Internal Access Controls
Access by TraphicLights personnel is restricted based on job responsibilities and business requirements.
Administrative access is limited to authorized personnel and is monitored and logged.
Infrastructure Security
Secure Hosting
Platform infrastructure is hosted using reputable cloud infrastructure providers that maintain industry-recognized security standards.
Security measures include:
- Network segmentation
- Firewall protections
- Infrastructure monitoring
- Availability controls
Environment Separation
Production, testing, and development environments are logically separated to reduce risk and protect customer information.
Backup and Recovery
We maintain backup procedures designed to support business continuity and data recovery.
Backups are:
- Protected against unauthorized access
- Retained according to operational requirements
- Regularly reviewed as part of recovery planning
AI Governance Security
As an AI governance platform, TraphicLights is designed to provide organizations with visibility and control over AI activity.
Security features may include:
- AI inventory management
- Agent ownership tracking
- Activity monitoring
- Audit logging
- Permission management
- Governance reporting
These capabilities help customers improve accountability and oversight within their AI environments.
Monitoring and Logging
We maintain monitoring capabilities designed to identify security events, operational issues, and unauthorized activity.
Monitoring may include:
- Authentication events
- Administrative actions
- System access activity
- API usage
- Infrastructure health
Security-relevant activities are logged and retained in accordance with operational requirements.
Vulnerability Management
We regularly review and improve platform security through:
- Security assessments
- Vulnerability monitoring
- Dependency management
- Software updates
- Security patching
Critical security issues are prioritized for remediation based on risk and impact.
Secure Development Practices
Security is integrated into our software development lifecycle.
Practices may include:
- Code review processes
- Dependency scanning
- Security testing
- Change management procedures
- Access controls for source code repositories
Incident Response
We maintain procedures for responding to security incidents.
Our incident response process includes:
Identification
Detection and assessment of potential security events.
Containment
Actions to limit impact and prevent further exposure.
Investigation
Analysis of affected systems and data.
Remediation
Corrective actions designed to address identified issues.
Communication
Notification of affected customers where required by law, contractual obligations, or applicable security commitments.
Third-Party Services
Our platform may integrate with third-party services, including AI providers, cloud platforms, and business applications.
While we evaluate third-party providers carefully, customers acknowledge that third-party services operate under their own security practices and policies.
Customers are responsible for reviewing and approving third-party integrations used within their environment.
Customer Responsibilities
Security is a shared responsibility.
Customers are responsible for:
- Managing user permissions
- Protecting account credentials
- Enabling available security controls
- Reviewing connected integrations
- Maintaining compliance with applicable laws and regulations
Customers should promptly notify us of suspected security incidents involving their accounts.
Data Privacy
We are committed to protecting customer privacy.
Unless explicitly agreed otherwise:
- Customer data is not sold.
- Customer data is not shared with unrelated third parties.
- Customer data is not used to train proprietary AI models.
- Customer data remains under customer control.
Additional details are available in our Privacy Policy.
Security Reporting
We encourage responsible reporting of security vulnerabilities.
Security concerns may be reported to:
Email: security@traphiclights.ai
Reports should include sufficient information to allow investigation and remediation.
Continuous Improvement
Security threats continue to evolve, and so do our security practices.
We regularly review our policies, controls, and procedures to ensure we continue providing a secure platform that helps organizations govern AI safely and responsibly.
For questions regarding this Security Policy, please contact:
Email: security@traphiclights.ai