Security built into every layer.
Your supply chain data is protected by industry-leading encryption, audit logs, and access controls. Learn how NormaTrack keeps your sensitive information secure.
Last updated: March 30, 2026
Data Protection
NormaTrack uses industry-standard encryption to protect your data in transit and at rest:
- In Transit: All data is encrypted using HTTPS/TLS 1.3 protocols.
- At Rest: Data is encrypted at the database level using industry-standard encryption algorithms.
- Database Isolation: Data is isolated per company with row-level security enforced at the database level.
- Authentication: All authentication is handled via JWT tokens with encrypted cookies.
Authentication & Access Control
Role-Based Access Control (RBAC)
NormaTrack implements four permission levels to control access to sensitive operations:
- Owner: Full administrative access, including billing and workspace settings.
- Admin: Can manage users, modify data, and configure integrations.
- Editor: Can create, import, and modify product passports.
- Viewer: Read-only access to product passports and reports.
Password Security
All passwords are hashed using bcrypt with a minimum of 12 rounds. Minimum password requirements are enforced to ensure strong credentials.
Change Tracking
All user changes and data modifications are logged with timestamps and user identification for audit purposes.
Audit Logging
Every action on the NormaTrack platform is recorded in an immutable audit log. This includes:
- Who performed the action (user identification).
- What was changed (detailed delta information).
- When it occurred (precise timestamps).
- Context around the change (reason, affected records).
Audit logs cover all platform operations including imports, updates, exports, user management, and system configuration changes.
All audit logs are fully exportable (CSV / JSON) for external compliance reviewers.
Private Document Sharing
Confidential documents and product passports can be shared securely via time-limited or one-time tokens:
- No password credentials required for recipients.
- Time-limited access that automatically expires.
- One-time token access for maximum security.
- Full logging of all token access for audit trails.
- Instant revocation by platform administrators.
This enables secure collaboration with suppliers, auditors, and regulators without compromising security.
Compliance & Regulations
Digital Product Passport (DPP) Regulations
NormaTrack is built from the ground up to align with EU Digital Product Passport regulations. Our platform supports:
- Structured, machine-readable formats (JSON/CSV) for regulatory submissions.
- Complete audit trails for compliance verification.
- Data export capabilities for regulatory audits.
GDPR Compliance
NormaTrack is committed to GDPR compliance and data privacy:
- Data processing agreements available upon request.
- User data deletion available upon verified request through the admin panel.
- Data portability support for exporting all workspace data.
- Privacy policy transparent about data usage and retention.
Infrastructure & Hosting
NormaTrack data is hosted in EU-based infrastructure with redundancy and recovery procedures in place to support operational resilience and compliance requirements.
Report Security Issues
If you discover a security vulnerability, we appreciate your responsible disclosure:
- Email security@normatrack.com with detailed information about the vulnerability.
- Do not publicly disclose the issue before we have a chance to respond.
- We will acknowledge receipt within 24 hours.
- We will provide regular updates on remediation progress.
Thank you for helping us keep NormaTrack secure.
International Data Transfers
Your data is primarily hosted in the EU. Where transfers occur outside the EEA (for example, to specific third-party service providers), we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): We utilize SCCs as a legal mechanism to ensure GDPR-compliant data transfers to subprocessors outside the EU/EEA.
- Data Processing Agreements (DPAs): All subprocessors sign strict Data Processing Agreements with privacy and security obligations.
- Adequacy Assessments: Subprocessors undergo rigorous security and privacy assessments before onboarding.
For a complete list of our subprocessors and their locations, see our Subprocessor Registry.
Governing Law
These security terms and practices are governed by and construed in accordance with the laws of France, without regard to conflict of law principles. Exclusive jurisdiction for the resolution of any dispute arising out of security practices shall reside in the competent courts of Paris, France.