← Security

CheckTrail data flow diagram

The full written description (what each system sees, retention, access) is in ../data-flow.md. Last updated 2026-09-25.

Systems and data

flowchart TB
  subgraph Firm["Broker-dealer"]
    U["Staff browser / phone app"]
    IDP["Firm identity provider<br/>(optional SSO)"]
    EX["Examiner<br/>(time-limited link)"]
  end

  subgraph NF["Netlify (US)"]
    APP["CheckTrail app<br/>(serverless functions)"]
    CRON["Scheduled function<br/>every 15 min"]
  end

  subgraph AWS["AWS, CheckTrail account (us-east-1/2)"]
    S3[("S3 records bucket<br/>Object Lock COMPLIANCE<br/>SSE-KMS")]
    KMS["KMS key<br/>(customer-managed)"]
    TX["Textract"]
    LOG[("Access-log bucket")]
  end

  DB[("Neon Postgres (US)")]
  RS["Resend (email)"]
  ST["Stripe (billing)"]
  SE["Sentry (errors)"]

  U -->|"TLS: photos, blotter fields, session cookie"| APP
  EX -->|"TLS: one export package, read-only"| APP
  IDP -.->|"signed SSO assertion"| APP
  CRON -->|"secret header"| APP
  APP -->|"TLS: all structured data<br/>(account nos. encrypted; routing/acct last 4 only)"| DB
  APP -->|"TLS 1.2+: images, CSVs, exam ZIPs (write-once)"| S3
  S3 --> KMS
  APP -->|"decrypt field-encryption key"| KMS
  S3 --> LOG
  APP -->|"TLS: check image bytes (opt-out policy required)"| TX
  APP -->|"TLS: email address + short alert text<br/>(no images, no account numbers)"| RS
  APP -->|"TLS: firm name, billing email, seat count"| ST
  APP -->|"TLS: scrubbed errors<br/>(no bodies, cookies, 6+ digit runs)"| SE

Trust boundaries

flowchart LR
  subgraph B1["Boundary 1: public internet"]
    U["Users, examiners"]
  end
  subgraph B2["Boundary 2: CheckTrail-controlled"]
    APP["App on Netlify"]
    S3["AWS account"]
    DB["Neon project"]
  end
  subgraph B3["Boundary 3: other subprocessors"]
    RS["Resend"]
    ST["Stripe"]
    SE["Sentry"]
  end
  U -- "HTTPS, session + 2FA or SSO" --> APP
  APP -- "IAM user, least privilege" --> S3
  APP -- "restricted DB role checktrail_app" --> DB
  APP -- "API keys (Netlify secrets)" --> RS & ST & SE

Notes:

  • The optional Anthropic OCR provider is not shown; it is off and must not be used with real data until a zero-data-retention agreement is signed.
  • Card and bank details are entered on Stripe's own pages and never pass through CheckTrail.