CheckTrail data flow diagram
The full written description (what each system sees, retention, access) is in
../data-flow.md. Last updated 2026-09-25.
Systems and data
flowchart TB
subgraph Firm["Broker-dealer"]
U["Staff browser / phone app"]
IDP["Firm identity provider<br/>(optional SSO)"]
EX["Examiner<br/>(time-limited link)"]
end
subgraph NF["Netlify (US)"]
APP["CheckTrail app<br/>(serverless functions)"]
CRON["Scheduled function<br/>every 15 min"]
end
subgraph AWS["AWS, CheckTrail account (us-east-1/2)"]
S3[("S3 records bucket<br/>Object Lock COMPLIANCE<br/>SSE-KMS")]
KMS["KMS key<br/>(customer-managed)"]
TX["Textract"]
LOG[("Access-log bucket")]
end
DB[("Neon Postgres (US)")]
RS["Resend (email)"]
ST["Stripe (billing)"]
SE["Sentry (errors)"]
U -->|"TLS: photos, blotter fields, session cookie"| APP
EX -->|"TLS: one export package, read-only"| APP
IDP -.->|"signed SSO assertion"| APP
CRON -->|"secret header"| APP
APP -->|"TLS: all structured data<br/>(account nos. encrypted; routing/acct last 4 only)"| DB
APP -->|"TLS 1.2+: images, CSVs, exam ZIPs (write-once)"| S3
S3 --> KMS
APP -->|"decrypt field-encryption key"| KMS
S3 --> LOG
APP -->|"TLS: check image bytes (opt-out policy required)"| TX
APP -->|"TLS: email address + short alert text<br/>(no images, no account numbers)"| RS
APP -->|"TLS: firm name, billing email, seat count"| ST
APP -->|"TLS: scrubbed errors<br/>(no bodies, cookies, 6+ digit runs)"| SE
Trust boundaries
flowchart LR
subgraph B1["Boundary 1: public internet"]
U["Users, examiners"]
end
subgraph B2["Boundary 2: CheckTrail-controlled"]
APP["App on Netlify"]
S3["AWS account"]
DB["Neon project"]
end
subgraph B3["Boundary 3: other subprocessors"]
RS["Resend"]
ST["Stripe"]
SE["Sentry"]
end
U -- "HTTPS, session + 2FA or SSO" --> APP
APP -- "IAM user, least privilege" --> S3
APP -- "restricted DB role checktrail_app" --> DB
APP -- "API keys (Netlify secrets)" --> RS & ST & SE
Notes:
- The optional Anthropic OCR provider is not shown; it is off and must not be used with real data until a zero-data-retention agreement is signed.
- Card and bank details are entered on Stripe's own pages and never pass through CheckTrail.