Resources

Security & compliance

Our approach to protecting and hosting your data.

Last updated: 30 July 2026

Your schedules and estimates hold sensitive information: project values, team workload, supplier prices. Here is how they are protected, without unnecessary jargon.

Hosting and infrastructure

Tropic applications are delivered through Cloudflare, and application data is hosted on Supabase, a platform built on PostgreSQL. Database servers are located in the European Union.

All traffic between your browser and our servers is encrypted with HTTPS/TLS. Data is encrypted at rest by the hosting provider.

Data isolation

Each design office has its own organisation. An organisation's data is only accessible to its members — isolation is enforced at database level, not merely in the interface. A query issued by one user cannot technically return another organisation's data.

Within an organisation, roles define who can view, edit or administer: team member, department lead, management.

Authentication

Access is by named account with a password. Passwords are never stored in clear text: only a cryptographic hash is kept, including by us.

Every member has their own credentials. Sharing a single account between several people is discouraged — it makes the action history meaningless.

Backups and reversibility

The hosting platform performs regular database backups.

Independently of that, your data remains exportable at any time: Tropic Planning and Tropic Estimating produce Word and Excel exports, with no request to us and no intervention on our side. We encourage you to keep your own exports of important documents — it is the best safeguard, whatever solution you use.

On termination, you have thirty days to retrieve all of your data.

Personal data and GDPR

The data you enter in the applications belongs to you. For that data, Tropic acts as a processor within the meaning of the GDPR: we process it solely to provide the service, never for any other purpose.

No customer data is sold or used for advertising. The public website sets no tracking cookies, and the analytics in use collect no personal data.

Full details are set out in the privacy policy.

Confidentiality of your projects

We do not access the content of your projects. Technical intervention on your data only takes place at your request, as part of a support case, and is limited to what the request requires.

What we do not claim

In the interest of transparency: Tropic is a young company. We do not currently hold ISO 27001 certification or French health-data (HDS) accreditation, and we do not publish a contractual uptime figure.

We commit to what we control: strict isolation, data exportable without condition, infrastructure hosted in the European Union, and a support reply within one business day. If your organisation has additional formal requirements, let's discuss them before you subscribe.

Reporting an issue

Spotted a vulnerability or unusual behaviour? Write to contact@groupetropic.com. Any serious report is reviewed as a priority.