Case studies
A Braintree project, built together with their team
Tools

Sending design files to vendors, with proof of every step

SecureTrace is Braintree’s platform for sending proprietary engineering files to outside vendors, replacing ad-hoc Dropbox links that failed a compliance audit. We built it together with Braintree’s team: every release is classified, approved, time-limited and recorded, so an auditor can see who sent what, to whom, when, and who approved it.

ISO/IEC 27001 Annex A controls mapped in the product
26ISO/IEC 27001 Annex A controls mapped in the product
confidential files never leave without a manager’s decision
Approvedconfidential files never leave without a manager’s decision
every link expires, with a download limit
Time-boxedevery link expires, with a download limit
an audit trail no role can edit
Tamper-evidentan audit trail no role can edit
securetrace · dashboard

SecureTrace dashboard: active transfers, approvals waiting and lapsed agreements

SecureTrace dashboard: active transfers, approvals waiting and lapsed agreements
The dashboard: live releases with their expiry and download limits, approvals waiting, and vendors whose agreements have lapsed. Everything shown is demo data.
The problem

Dropbox links can’t pass an audit

Engineering teams were sending design files to outside vendors through Dropbox. Compliance rejected it, because nothing could answer an auditor’s basic questions.

Before

Shared links

  • No record of who sent what, to whom, or who approved it
  • A restricted design handled the same as a public brochure
  • Links that live forever, with no way to take them back
  • Files going to vendors whose NDA lapsed long ago
  • Nothing to hand an auditor

After

SecureTrace

  • Every release has a sender, an approver, a recipient and a reason
  • Every file is classified, and the class decides the rules
  • Links expire, downloads are capped, and access can be revoked in one click
  • The vendor’s agreement is checked before anything is sent
  • A sealed, verifiable audit extract, ready for the auditor
How it works

From upload to disposal, every step on the record

  1. Staff

    Upload and classify

    • Public, Internal, Confidential, Restricted
    • Scanned and encrypted
  2. SecureTrace

    Check and approve

    • Vendor agreement valid?
    • Class within the vendor’s ceiling?
    • Manager approves
    • Link issued, time-limited
  3. Vendor

    Receive

    • One-time code
    • Watermarked
    • Download limit
  4. Afterwards

    Expire and dispose

    • Link dies on time
    • Disposal certificate
    • Sealed audit record
securetrace · transfers · TRF-2026-0117

A transfer's chain of custody, from creation to download, including a blocked forward attempt

A transfer's chain of custody, from creation to download, including a blocked forward attempt
One transfer’s chain of custody: created, NDA checked, approved, link issued, identity verified, downloaded, and a forward attempt to a personal Gmail address blocked. Each step carries its ISO control.
securetrace · new transfer

The new transfer wizard

The new transfer wizard
The send wizard: files, recipient, purpose and policy. The transfer takes the highest classification among its files.
securetrace · approvals

The approvals queue

The approvals queue
Approvals: confidential and restricted files wait for a manager, who sees the vendor’s agreement status before deciding.
Built for auditors

Controls enforced by the system, not by a policy document

Every rule is checked on the server, so it holds no matter which screen or API a request comes through.

Classification with teeth

A folder’s class is the floor for everything in it, and each class sets its own link life, download limit, watermark and identity check.

Vendor agreements checked

No agreement, no release. When an NDA lapses, a scheduled sweep withdraws the links that vendor already has.

Verified recipients

Vendors confirm a one-time code sent to the invited address. Staff sign in with single-use links, so there are no passwords to leak.

A trail nobody can edit

The audit log is append-only and hash-chained, and it is sealed hourly into write-once storage. Any edit is detectable.

Signed evidence

Audit extracts are sealed with a SHA-256 hash and an Ed25519 signature that an auditor can verify offline.

Disposal, on record

When a release ends, the vendor is asked to destroy their copies, and the certificate they issue closes the record.

Blocked, and counted

Forwards outside the approved domain, expired links and over-limit downloads are refused and logged against the vendor.

Two-person policy changes

A policy change is proposed by one administrator and takes effect only when a different one approves it.

Nothing lives forever

Every link has an expiry and a download ceiling, and can be revoked in one click.
securetrace · policies

The policies page with a change awaiting a second administrator

The policies page with a change awaiting a second administrator
Policies: the rules every transfer is held to. One administrator proposes a change, and it is enforced only once a second approves it.
securetrace · audit log

The audit log

The audit log
The audit log: every action on every file and transfer, filterable and exportable as sealed evidence.
securetrace · ISO mapping

ISO/IEC 27001:2022 control mapping

ISO/IEC 27001:2022 control mapping
The ISO/IEC 27001:2022 mapping, live in the product: which control each feature answers, and how much of it.
securetrace · vendors

The vendor registry with agreements and risk tiers

The vendor registry with agreements and risk tiers
Vendors, each with an agreement, a risk tier, and the highest class of file they may receive.
securetrace · reports

Management reports

Management reports
Reports for management review: releases by class and by vendor, blocked attempts, and expiring agreements.
Our part

Built alongside Braintree’s team

SecureTrace is Braintree’s product. We worked with their team on it, from the clickable prototype used to agree the design, to the real authentication, encrypted storage, malware scanning and database underneath it.

A prototype that answers the audit

Every screen was built to answer one of the five gaps compliance raised, so the design could be agreed before the build.

Security that is real, not shown

Server-side checks, encryption at rest, malware scanning and a tamper-evident trail sit under the screens.

Tested against the controls

Tests are tagged with the ISO control they prove, so the mapping is backed by behaviour rather than claims.
Built with

The pieces underneath

  • Next.js
  • React
  • TypeScript
  • Postgres
  • S3 with Object Lock
  • Ed25519 signing
  • Malware scanning
  • Docker
  • Caddy
  • Vitest

Tell us where the business hurts. We'll tell you if AI fixes it.

Thirty minutes with the engineers who'd actually build it. You leave with an honest read on whether it's worth doing, what it would take, and what it would cost.