Security
An overview of the controls that protect brand and supplier data in the Trama platform: processing confined to the European Union, encryption in transit and at rest, least-privilege access and a complete audit trail.
Last updated: 19 August 2026
European processing
Every component that handles customer data runs within the European Union: the database in Ireland, file storage in Milan, the application in Frankfurt and the AI inference endpoints on European infrastructure. Authenticated traffic does not transit non-European networks.
The public passport page is distributed through a global content network, so that a code printed on a garment resolves anywhere in the world. That page carries the product information a passport is required to publish and contains no personal data.
Confidentiality of supplier documents
Supplier documents are held in private storage that is never publicly readable. Only the passport is published, and its contents are determined field by field before release: the brand reviews the exact set of fields it is publishing before committing to it.
Encryption
All traffic is served over TLS, and plain HTTP is redirected before it reaches the application. Stored files are encrypted at rest and versioned, so that an incorrect change can be reverted.
Supplier access without credentials
Suppliers submit documents through a single-purpose link with a limited lifetime. No account is created and no password is issued, which removes a category of credential risk from a supply chain in which credential hygiene cannot be enforced.
Human confirmation before publication
Automated extraction proposes values; it does not commit them. Every item of information is confirmed by a named user at the brand before it can enter a passport, and that confirmation is recorded with the evidence it was based on.
Audit trail and immutability
Confirmed evidence and the audit log are append-only. Published passports are immutable: a correction is issued as a new version and the previous version remains accessible, so that a reference cited by an authority continues to resolve to the content that was cited.
Scan analytics
Scan events are recorded at country level only. No visitor identifier is assigned, no cookie is set and nothing is written to the device. Aggregated views apply a minimum group size, so that an individual scan cannot be isolated.
Alignment with ISO/IEC 27001
The controls described here follow the ISO/IEC 27001 control set: processing confined to the European Union, encryption in transit and at rest, least-privilege access, an append-only audit trail and no personal data in the public layer.
Formal certification is part of our roadmap as the company grows. In the meantime we provide architectural detail and evidence of these controls on request, for security reviews and vendor due diligence.
Reporting a vulnerability
Write to hello@tramaproof.com with "security" in the subject line. Good-faith reports are welcome and are never met with legal action.