Security
Last updated 2026-08-16
Reporting a vulnerability
Found a security issue in TrainerCue? Email security@trainercue.com and we will respond quickly, keep you informed, and credit you if you want. Please give us a reasonable chance to fix an issue before disclosing it publicly.
How TrainerCue is secured
Traffic is encrypted in transit (TLS) and data is encrypted at rest (AES-256) by our hosting infrastructure. Every workspace is isolated at the database layer with row-level security, enforced by the database on every query and verified continuously by an automated adversarial test suite. Stored files are private and served only through short-lived signed links. A strict Content-Security-Policy keeps third-party scripts and trackers out of the application, and an automated test keeps it that way.
Our infrastructure providers maintain independent security certifications including SOC 2 Type II and ISO 27001. TrainerCue itself is an independent company and has not yet undergone a third-party security audit. Access to production systems is limited to the founder.