Triad Global Triad Core

Security

Last updated 4 October 2026. The technical and organisational measures that protect customer records in Triad Core. This page is Annex II of the data processing addendum. We list only what is in place today.

Hosting and encryption

  • Hosted on Google Cloud in the United States (us-east4): Cloud Run for the application, Cloud SQL for PostgreSQL for the database, Cloud Storage for files. Google Cloud holds SOC 2 and ISO/IEC 27001 certifications for these services.
  • All traffic over HTTPS (TLS), with HTTP Strict Transport Security for two years including subdomains. Data encrypted at rest by Google Cloud.
  • The database has no public address; the application reaches it inside a private network. Secrets are kept in Google Secret Manager, never in code.
  • Credentials of connected systems (mailboxes, integrations) are sealed with a separate encryption key and never sent to a browser. National identity numbers in HR records are encrypted in the database.
  • Connected Google and Microsoft mailboxes: when a person disconnects, Triad Core asks Google to revoke its access, deletes the tokens at once and deletes the copies of emails nobody filed on a record. A personal mailbox is visible only to its owner; Triad staff do not read mailbox content except as the privacy notice allows.

Separation of customers

Every business table carries the workspace it belongs to, and PostgreSQL row-level security, forced for the application's own database role, lets a request see only the rows of the workspace it was checked for. A query without that check returns nothing rather than another customer's data.

Access control

  • Accounts by invitation only; no self sign-up. Passwords are stored only as salted hashes. Sign in with Google is available.
  • Two-step sign-in with an authenticator app and one-time backup codes, which each person can switch on in Account and security; repeated wrong codes are rate limited and locked. A company can require it for all its people.
  • Single sign-on with the company's own identity provider (OIDC or SAML 2.0). A provider works only after a DNS record proves the company owns its email domain, and opens only accounts of people already invited to that company. A company can require it for its domain.
  • Role-based permissions per module (view, create, edit, delete, approve, export, manage), record scope (own, team, site, all) and hidden fields for prices, costs, margins and salaries, enforced on the server.
  • Sign-in, password, invitation, search and public links are rate limited.
  • Triad staff reach customer workspaces only through named accounts with the platform role, for support the customer asked for or to keep the service secure.

Application security

  • Content Security Policy, frame blocking, no content-type sniffing, strict referrer policy and permissions policy on every page.
  • Uploaded files limited by type and size; images are re-encoded and stripped of location data. Files are served only through permission-checked downloads, never by public storage addresses.
  • Outbound calls to customer-configured addresses pass a server-side request forgery guard.
  • Dependencies are checked for known vulnerabilities before each release; the automated test suite (unit, permission and end-to-end walks) runs before each deploy.

Audit trail and logging

Every change to documents, records, settings, roles, entitlements, members, files and emails is written to an append-only audit trail, hash-chained per workspace, that the application cannot edit. Requests are logged with an identifier, without request bodies or secrets. Error logs trigger alerts.

Backups and continuity

Daily database backups with point-in-time recovery, kept for 7 days, in the same region. Files are stored with Google Cloud's redundancy. Items deleted in the application first go to a recycle bin where they can be restored.

Incidents

We investigate security events as they are detected, contain and fix them, and notify affected customers of a personal data breach without undue delay and within 48 hours of becoming aware of it (see the data processing addendum).

People

Access for Triad personnel and contractors is limited to what their work needs and covered by confidentiality obligations. Access is removed when it is no longer needed.

Planned

  • Malware scanning of uploaded files and email attachments (ClamAV, run privately in our own cloud project; built and tested, to be switched on for the production service).

Report a vulnerability

Email office@triadglobal.org with the subject "Security". Please give us a reasonable time to fix an issue before disclosing it, and do not access other customers' data while testing.