Security

Security designed around controlled access and traceable operations

TrackCRE limits access by user and role, verifies sensitive payment events, and keeps administrative workflows separate from customer workspaces.

Named-user accounts

Workspace access uses individual accounts. Shared credentials are not permitted, and team membership is managed by account owners.

Role-based access

Customer, account-owner, and administrator access is checked at the data layer. Administrative pages and operations are not available to ordinary members or signed-out visitors.

Billing isolation

Subscription state is accepted from signed payment-provider events, not browser redirects. Test subscriptions are separated from live access and revenue.

Operational safeguards

Private service credentials stay outside browser code. Administrative changes are recorded, and scheduled jobs use controlled endpoints and stale-lock recovery.

What we state carefully

No online service can guarantee absolute security. This page describes current product controls and does not claim a certification, audit result, or regulatory status that TrackCRE has not separately documented.

Customer responsibilities

  • Use an individual account and a unique password.
  • Remove team members who no longer need access.
  • Do not share exported data beyond your permitted use.
  • Report suspected unauthorized access promptly.

Report a security concern

Send a concise description and affected page to help@trackcre.com. Do not include passwords, payment card details, or unnecessary personal information.