Sending design files to vendors, with proof of every step
SecureTrace is Braintree’s platform for sending proprietary engineering files to outside vendors, replacing ad-hoc Dropbox links that failed a compliance audit. We built it together with Braintree’s team: every release is classified, approved, time-limited and recorded, so an auditor can see who sent what, to whom, when, and who approved it.
- ISO/IEC 27001 Annex A controls mapped in the product
- 26ISO/IEC 27001 Annex A controls mapped in the product
- confidential files never leave without a manager’s decision
- Approvedconfidential files never leave without a manager’s decision
- every link expires, with a download limit
- Time-boxedevery link expires, with a download limit
- an audit trail no role can edit
- Tamper-evidentan audit trail no role can edit
Dropbox links can’t pass an audit
Engineering teams were sending design files to outside vendors through Dropbox. Compliance rejected it, because nothing could answer an auditor’s basic questions.
Before
Shared links
- No record of who sent what, to whom, or who approved it
- A restricted design handled the same as a public brochure
- Links that live forever, with no way to take them back
- Files going to vendors whose NDA lapsed long ago
- Nothing to hand an auditor
After
SecureTrace
- Every release has a sender, an approver, a recipient and a reason
- Every file is classified, and the class decides the rules
- Links expire, downloads are capped, and access can be revoked in one click
- The vendor’s agreement is checked before anything is sent
- A sealed, verifiable audit extract, ready for the auditor
From upload to disposal, every step on the record
Staff
Upload and classify
- Public, Internal, Confidential, Restricted
- Scanned and encrypted
SecureTrace
Check and approve
- Vendor agreement valid?
- Class within the vendor’s ceiling?
- Manager approves
- Link issued, time-limited
Vendor
Receive
- One-time code
- Watermarked
- Download limit
Afterwards
Expire and dispose
- Link dies on time
- Disposal certificate
- Sealed audit record
Controls enforced by the system, not by a policy document
Every rule is checked on the server, so it holds no matter which screen or API a request comes through.
Vendor agreements checked
Verified recipients
A trail nobody can edit
Signed evidence
Disposal, on record
Blocked, and counted
Two-person policy changes
Nothing lives forever
Built alongside Braintree’s team
SecureTrace is Braintree’s product. We worked with their team on it, from the clickable prototype used to agree the design, to the real authentication, encrypted storage, malware scanning and database underneath it.
A prototype that answers the audit
Security that is real, not shown
Tested against the controls
The pieces underneath
- Next.js
- React
- TypeScript
- Postgres
- S3 with Object Lock
- Ed25519 signing
- Malware scanning
- Docker
- Caddy
- Vitest