Your prototypes are your IP. We built Proto Tracker to protect it.
Unreleased hardware is among the most sensitive information a company has. Here's exactly how we handle it, in plain language.
Encrypted at rest
All organisation data is stored in Amazon DynamoDB, encrypted with AES-256 using an AWS KMS customer-managed key dedicated to Proto Tracker, with automatic yearly key rotation. Backups are encrypted with the same key.
Encrypted in transit
Every connection to the app and API uses HTTPS with TLS 1.2 or newer, served through Amazon CloudFront with HSTS. There is no plain-HTTP path to your data.
Never shared, never sold
We don't sell data, show adverts, or use your designs to train AI models. The only companies that process data for us are AWS (hosting and email) and Stripe (payments), and Stripe only ever sees billing details.
Isolated per organisation
Every design, prototype and history record is partitioned by organisation. The API checks your membership and role on every request, and our automated tests check that other organisations can't see your data.
Append-only history
Each change is committed in the same database transaction as its history entry. The application has no way to edit or delete history, so the record of who changed what, and when, stays trustworthy.
Yours to export or delete
Download everything as JSON at any time. Deleting an organisation permanently removes its data. Encrypted point-in-time backups expire within 35 days.
Controls in the product
- Passwords
- Hashed with Argon2id, the winner of the Password Hashing Competition. We check new passwords against common choices and never store them in plain text.
- Two-factor authentication
- Every account, on every plan, can require a code from an authenticator app at sign-in, with single-use recovery codes. A password reset can't bypass it, and we email you when it's turned on or off.
- Sessions
- Access tokens last 15 minutes and are kept only in memory. Refresh tokens are httpOnly, SameSite=Strict cookies, rotated on every use, and you can sign out of every device at once.
- Abuse protection
- Sign-in, sign-up, password reset and invitations are rate limited. Sign-in doesn't reveal whether an email address has an account.
- One-time links
- Email verification, password reset and invitation links are single-use and expire. We store only a SHA-256 hash of each token.
- Least privilege
- Each piece of our infrastructure has only the permissions it needs. The API function can reach its own tables and nothing else.
- No third-party code in the app
- The web app loads no third-party scripts, fonts or trackers. Everything it runs is served from our own origin.
- Roles
- Owner, admin, editor and read-only viewer. Billing, members and exports are limited to admins and owners.
- Payments
- Card details go straight to Stripe (PCI DSS Level 1) through Stripe Checkout. They never touch our servers.
Who else touches your data
A deliberately short list. We'll give 30 days' notice by email before adding a sub-processor that can access customer data.
| Company | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, database, encryption keys, CDN and transactional email | Sydney, Australia (ap-southeast-2); email may transit AWS global infrastructure |
| Stripe, Inc. | Subscription billing and payment processing. Receives billing contact and payment details only | United States and other Stripe regions |
Processing on your behalf is covered by our data processing agreement, which includes the EU Standard Contractual Clauses and the UK Addendum.
The marketing website uses no cookies, analytics or tracking scripts. See our privacy policy for details.
Responsible disclosure
Found a vulnerability?
Email security@proto-tracker.com. We acknowledge reports within three working days, keep you updated, and won't take legal action against good-faith research that avoids privacy violations and service disruption. Our security.txt has the details.
Security questions
Is my data encrypted?
Yes. Data is encrypted in transit with TLS 1.2+ and at rest with AES-256 using an AWS KMS customer-managed key that is dedicated to Proto Tracker and rotated automatically. Backups are encrypted too.
Do you share my data with third parties?
No. We never sell or share your engineering data, run advertising, or train AI models on it. Our only sub-processors are AWS, which hosts the service, and Stripe, which handles payments and only receives billing details.
Where is my data stored?
In Amazon Web Services' Sydney region (ap-southeast-2). Customers who need data in another region can contact us.
Can Proto Tracker staff see my designs?
Access to production data is restricted to the service operator's engineering account, protected with multi-factor authentication, and used only to operate and support the service or where required by law. There is no staff browsing interface for customer data in the application.
Do you have SOC 2 or ISO 27001?
Not yet. Proto Tracker runs entirely on AWS infrastructure that holds those certifications, and our own controls are described on this page. If you need a security questionnaire completed, email us.
How do I report a vulnerability?
Email security@proto-tracker.com. We acknowledge reports within three working days and don't take legal action against good-faith research that respects user privacy.
Keep your prototypes' history safe.
Free for individual engineers. Business from $19 a month for 5 people, with a 1-month free trial.