Enterprise freight data deserves enterprise security.
Security is built in from day one — not bolted on after the first big customer asks. Here's the minimum bar we hold ourselves to.
- ✓Encryption in transit & at rest
All traffic encrypted; stored data — including attachments — encrypted at rest.
- ✓Tenant isolation
Strict multi-tenancy: Organization A can never access Organization B's users, RFQs or documents. Ever.
- ✓Role-based access control
Operators, reviewers and admins get exactly the permissions their job needs — nothing more.
- ✓Secure attachment storage
Documents stored securely with signed, temporary URLs — no permanent public links to customer freight data.
- ✓Audit logging
Every extraction, edit, approval and export is logged: who, what, when. The same trail your operators see, your security team can verify.
- ✓API authentication
Every API call authenticated; integrations scoped to the minimum access they need.
- ✓Secret management
Credentials, tokens and keys managed through a proper secrets store — never in code, logs or config files.
- ✓Retention & deletion policy
Automatic file deletion and retention rules, so customer data doesn't linger longer than it should.
- ✓No training on your data — without agreement
Customer data is never used for model training unless explicitly agreed. Your RFQs are your competitive data.
Your data never meets another forwarder's.
Forwarders compete. The architecture treats that as a first principle: organizations are fully isolated at the data layer — users, RFQs, documents, audit logs. There is no shared view, no cross-tenant query path, no accident waiting to happen.
Isolation model
Security questions? Let's talk through them.
Bring your infosec checklist to the pilot scoping call — we'll walk through every control against your requirements.
Book a pilot