Skip to main content
TrackVia logo

TrackVia

Regulatory evidence

Optimize your task management and automate processes with TrackVia's custom

trackvia.comProject managementLast verified 21 Sep 2026

TrackVia against third-party requirements

For each regulation, how many of the requirements it places on your vendors TrackVia’s public evidence reaches. Open one for every item with its date and source.

Documents on the trust centre

What the vendor lists, typed; public items can be read now, the rest are available on request.

6 documents listed on TrackVia’s trust centre

trust.trackvia.com
  • Business continuity and disaster recovery plan
    • Business Continuity Policyon request · seen 21 Sep 2026
    • Disaster Recovery Policyon request · seen 21 Sep 2026
  • HIPAA assessment report
    • TrackVia 2025 HIPAA Gap Analysis Final Reporton request · seen 21 Sep 2026
  • Incident response plan
    • Incident Response Policyon request · seen 21 Sep 2026
  • Security policy or overview
    • Information Security Policyon request · seen 21 Sep 2026
  • SOC 2 report
    • TrackVia 2025 SOC 2 Type 2 Final Reporton request · seen 21 Sep 2026

What the vendor says

Answers the vendor publishes to questions buyers ask, quoted with the link to where it says so.

  • Encryption

    Do you encrypt data in-transit & at rest?

    Data is encrypted in transit and at rest using AES-256, TLS v1.2.

    as of 21 Sep 2026Source

  • Penetration testing

    Does TrackVia conduct penetration tests?

    TrackVia engages with a third-party penetration testing firm on an annual basis. All areas of the TrackVia products and cloud infrastructure are in-scope for these assessments.

    as of 21 Sep 2026Source

  • Penetration testing

    Is vulnerability scanning and penetration testing performed?

    Internal vulnerability scans are performed at least annually, and the results are recorded and acted on by our Information Security team. TrackVia's source code is subject to SAST and DAST scanning as part of our Software Development Lifecycle. Third Party Penetration testing is conducted annually on both our network and platform. An abbreviated report is available via our Trust Center.

    as of 21 Sep 2026Source

  • Data retention and deletion

    How often do you perform backups, and what is your retention schedule?

    Full backups of customer data are taken daily and stored for 90 days. Customers data is automatically purged from our system 60 days after notice of contract termination.

    as of 21 Sep 2026Source

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.