Built to be trusted
Merit Tracker handles working hours, performance data and — where you enable it — screen captures. Here is exactly how that information is protected.
Encryption everywhere
All traffic runs over HTTPS/TLS, and data is encrypted at rest in our managed Postgres database and object storage.
Scoped access tokens
Sessions use signed JWTs with a limited lifetime. The desktop agent authenticates with its own separate token that can be revoked without touching your account password.
Role-based permissions
Every request is checked against the caller's role — Company, QC Admin or User — and against the company the record belongs to, so data can never cross company boundaries.
Tenant isolation
Every project, task, screenshot and file is bound to a company id, and queries are always filtered by the authenticated user's company.
Infrastructure
Managed hosting
Merit Tracker runs on managed cloud infrastructure with automated patching, isolated networking and continuous availability monitoring.
Backups
The production database is backed up automatically, allowing point-in-time recovery in the event of data loss or corruption.
Separation of environments
Development, staging and production are fully separated. Production credentials are never used outside the production environment.
Screen capture safeguards
Double opt-in
A screenshot is only ever taken when screen capture is enabled at the company level and on the specific project being worked on. Turning it off at either level stops capture immediately.
Only during tracked time
The desktop agent captures only while a work session is actively running. Stopping the timer stops capture.
Restricted visibility
Captured screenshots are visible only to administrators within your own company, and can be deleted — which also frees the storage they occupied.
Access and accountability
Least privilege
Access to production systems is limited to the engineers who need it, and is granted per person rather than through shared accounts.
Activity logging
Significant actions inside the product — logins, role changes, project and task updates, screenshot deletion — are recorded in an activity log your administrators can review.
Password handling
Passwords are hashed with a strong one-way algorithm and are never stored or transmitted in plain text. We cannot see your password.
Your data, your control
Export and deletion
You can request a copy of your company's data, or its deletion, at any time. Deleting a company removes its users, projects, files and screenshots.
Retention
We retain data for as long as your account is active. After closure, data is removed according to the schedule described in our Privacy Policy.
Sub-processors
We use a small set of vetted providers for hosting, storage, email delivery and payment processing. Each is bound by a data processing agreement.
Reporting a vulnerability
If you believe you have found a security issue in Merit Tracker, please tell us before disclosing it publicly. Send a description of the issue, the steps to reproduce it and any supporting material to our security address. We will acknowledge your report and keep you updated while we investigate.
Please do not run automated scans against production, access data that is not yours, or degrade the service for other customers while testing.
security@merittracker.comQuestions about security?
We are happy to walk your team through our practices, or complete a security questionnaire as part of your procurement process.