Trust

How Grovetrace protects your supplier and plot data

Plot geometry and supplier relationships are commercially sensitive before they are anything else. This page sets out how they are isolated, who can reach them, and where they are hosted.

Frankfurt
Where it runs
Per org
Tenancy boundary
Groups
How access is granted
11
Models writing to the audit trail
None
Analytics on this site
Controls

Security controls

Tenancy

Every query is scoped to your organization

Grovetrace is multi-tenant by Organization. Records reach their organization through an explicit map, never an inferred relationship: a helper that quietly returns nothing for one model is what a leak looks like from the inside. Anything the map does not cover is hidden by default, and a test fails if an audited model is missing from it.

Access

Access is granted through groups and policies

There is no per-user role anywhere in the interface. A policy attaches to a group and a person joins the group, so access can be read off an org chart instead of reconstructed from twelve individual grants. Administration is a separate context in the application, driven off the route, so nobody is in admin mode without knowing it.

Audit

A per-object audit trail, under the same scoping

Eleven models write to it: suppliers, land plots, their validation results and resolutions, batches, statements, documents, users, groups, memberships and invitations. Each entry is readable per object, and the trail sits under the same tenancy scoping as the data it describes. That last part is the one teams miss: registering a model for logging is a read decision as much as a write one.

Isolation

Cross-organization access is covered by automated tests

Tenant isolation is asserted by tests that prove one organization cannot read another’s data through the API, and they run on every change. It is the bar the platform is least willing to regress on: a failure there is a cross-tenant data breach involving somebody’s supplier list.

Infrastructure

Hosting and infrastructure

Region
Frankfurt (eu-central). Application, database, queue and background workers all run in the EU.
Transport
TLS on every connection, to the app and to the API.
Authentication
Email and password, exchanged for short-lived signed tokens that refresh silently and fall back to the login screen when they cannot.
Documents
Stored in object storage and reachable only through short-lived signed URLs. There is no public bucket path.
Secrets
Held in a managed secret store and injected at run time. Never committed, never baked into an image.
This site
A static build. It sets no cookies, runs no analytics, and serves its own fonts so no request for them leaves for another company.

The full subprocessor list, naming every third party the platform talks to and what each one receives, goes to customers on request. For that, a security questionnaire, a DPA, or a question this page does not answer, write to hello@grovetrace.com. You will get a direct answer, including when the answer is no.

Next step

Put the hard version of these questions to us

If you are the person who signs off on where supplier data goes, the demo is the place to interrogate it. Bring the questionnaire.

Where a control is not yet in place, you get that answer directly, on the call or in the questionnaire.