Enterprise Trust Center

Built for enterprises
that cannot afford
to compromise.

Shipsy is a Gartner-recognized, AI-native logistics platform trusted by 270+ global enterprises across 30+ countries. Every control, certification, and practice on this page reflects actual Shipsy policy — audited, documented, and available for review. The platform processes 5+ billion shipments per year across 270+ enterprises in 30+ countries.

🏅 SOC 2 Type II 🌐 ISO 27001 (BSI) 🇪🇺 GDPR Compliant 🛡️ AWS WAF + Shield 🔍 Biannual VAPT 📡 24/7 SIEM Monitoring 🔒 AES-256 + TLS 1.2 ☁️ AWS · GCP · Azure · On-Prem 🔐 Privacy by Design
99.9%
Uptime SLA
☁️ Multi
Cloud Agnostic
TLS 1.2
Encryption in Transit
2×/yr
Ext. VAPT
AES-256
Encryption at Rest
5B+
Shipments / Year
Trusted across industries
E-Commerce Retail & FMCG Logistics & 3PL Banking & Finance Healthcare Government Telecom Oil & Gas

Join Global Enterprises Embracing Autonomous Supply Chains

Trusted by 270+ enterprises across 30+ countries
01 · Governance
🏛️

Formal ISMS

ISO 27001-aligned ISMS. Dedicated ISO. Annual risk assessments. Policies reviewed at least annually. Reported to CTO.

02 · Assurance
🏅

Third-Party Audited

SOC 2 Type II certified. ISO 27001 via BSI. Biannual external VAPT. Annual TLPT red-team. Reports under NDA.

03 · Resilience

Always On

99.9% uptime SLA. Active-active Multi-AZ. RPO 5 min, RTO 25 min. Daily backups. DR tested annually.

04 · Privacy
🔐

Privacy by Design

GDPR compliant. SCCs & DPA available. DTIAs conducted. Data stays in your chosen region.

Why Global Enterprises Choose Shipsy for Mission-Critical Logistics

From global airlines to global postal operators and Fortune 500 retailers — Shipsy processes 5+ billion shipments per year for enterprises in regulated industries. We treat security as a first-class product feature: every control documented, independently tested, and available for review.

🌍

Deploy Anywhere, Your Rules

Cloud-agnostic on AWS, GCP, or Azure. Customer selects cloud provider and deployment region globally. On-premise also supported. Zero vendor lock-in.

Cloud-Agnostic
📋

Audit-Ready at Any Time

SOC 2 Type II report, ISO 27001 certificate, VAPT summaries, and completed DDQs available under NDA. Security briefings available for enterprise procurement teams.

Audit Ready
🔄

Enterprise-Scale Integration

8 integration methods: REST APIs, Webhooks, SDK, ETL Pipelines, File-based (CSV/Excel), Integration Marketplace, EDI, SFTP. ERP-ready: SAP S/4HANA, Oracle Fusion, Microsoft Dynamics 365, NetSuite. 100M+ API events/day processed reliably.

100M+ API Events/Day
🛡️

Defence-in-Depth

AWS WAF + GCP Armor, Shield DDoS, GuardDuty ML threat detection, ELK SIEM, SonarQube SAST, CodeRabbit, and Dependabot — all active, all the time.

Layered Security
🤝

Contractual Commitments

Data Processing Agreements with Standard Contractual Clauses. Custom DPA terms negotiable for enterprise. Sub-processor list maintained. NDA on all disclosures.

Legally Backed
👁️

Full Transparency

Real-time public Statuspage. Proactive incident communication. 72-hour breach notification. No security-through-obscurity. Everything documented.

Transparent

🏢 Company & Security Structure

Shipsy · Llama Logisol Pvt. Ltd. · Est. 2015
  • Dedicated CISO / security function reporting directly to CTO
  • Information Security Officer (ISO) owns all ISMS controls
  • All staff sign NDAs with post-employment confidentiality clauses
  • Security awareness training at onboarding + annually for all staff
  • Background checks on all prospective employees (where legally permitted)

🏅 Certifications & Compliance

SOC 2 · ISO 27001 (BSI) · GDPR
  • SOC 2 Type II — Certified (report available under NDA)
  • ISO 27001:2022 — Certified via BSI (British Standards Institution)
  • GDPR — Compliant; DPA + SCCs available
  • Cyber Insurance — Active policy maintained

🛡️ Security Testing Calendar

Continuous · Quarterly · Biannual · Annual
  • Continuous — SonarQube + CodeRabbit SAST, 24/7 SIEM, vulnerability scanning, Playwright + Appium E2E tests in CI/CD
  • Quarterly — Firewall rule reviews, production access rights reviews, Docker image scanning via AWS ECR
  • Biannual — External VAPT (PII Encryption tested), DDoS simulation exercises
  • Annual — TLPT / red-team exercises, IRP tabletop drills, DR failover tests (Multi-AZ and Multi-Region)

🚨 Incident Response

Documented IRP · 4 Severity Levels · 72h GDPR Notification
  • Documented IRP with escalation matrix and named roles
  • Four severity levels: Low / Medium / High / Critical with defined triggers
  • Supervisory authority notified within 72 hours
  • Mandatory RCA for all High / Critical events
  • No major security breaches reported
🏅

SOC 2 Type II

Independent audit of security, availability, processing integrity, confidentiality, and privacy controls over a sustained observation period.

TypeSOC 2 Type II
AuditorIndependent third party
ScopeAll 5 Trust Services Criteria
📄 Available under NDA
🌐

ISO 27001:2022

International standard for Information Security Management Systems (ISMS), demonstrating systematic management of information security risks.

StandardISO 27001:2022
Certifying BodyBSI (British Standards Institution)
CertificateAvailable on request
📄 Available on request
🇪🇺

GDPR Compliance

Full compliance with EU GDPR. DPA and Standard Contractual Clauses available. Privacy by Design embedded in all product development.

RegulationEU GDPR
RoleData Processor
DPAAvailable on request
📄 DPA + SCCs available
🔍
CATEGORIES
All questions111
🏛️ Governance & Strategy8
⚖️ Risk Management11
👥 Personnel & Training5
🌐 Network & Perimeter15
🔍 Vulnerability & SDLC8
🔑 Access & Identity11
📦 Data Protection & Privacy14
🚨 Incident Response & DR8
🤝 Third Parties & Suppliers9
🔄 Business Continuity14
📊 Data Quality & Governance8
Showing all 111 questions
🏛️ Governance & Strategy 8 questions
SEC-1Is there a dedicated Information Security function / CISO or ISO in your organisation?

Yes, our organisation has a dedicated Information Security function led by a Chief Information Security Officer (CISO). The CISO is responsible for overseeing all aspects of information security management, including policy development, risk management, compliance, incident response, and continuous monitoring of security controls across our infrastructure.

SEC-2Is there a defined Information Security Strategy?

Yes, we have a defined Information Security Strategy. Our strategy encompasses a comprehensive set of policies, procedures, and technical measures aimed at protecting information assets and ensuring compliance with industry standards. These measures include robust access controls, data encryption, and regular security assessments such as vulnerability assessments and penetration testing (VAPT). We maintain policies for data security and privacy lifecycle management, infrastructure and virtualization security, and identity and access management. Our platform is also compliant with security standards like ISO, and SOC 2, reinforcing our commitment to maintaining a high-security posture.

SEC-3Does your company hold Information Security certifications (ISO 27001, SOC2, …)?

Yes, SOC 2 Type 2 and ISO 27001 certifications are maintained. Reports and VAPT results are updated annually and available on request, reflecting global best practice adherence

SEC-4How frequently is your Information Security Policy updated ?

We review the information security policy every 3 months

SEC-5Is your Information Security Policy aligned with PCI DSS ?

We do not store or process any end user confidential Credit card or banking account information within Shipsy's systems. Instead rely on PCI DSS-compliant third parties (like Stripe, Razorpay, PayPal, Adyen, etc.) to handle payments end-to-end. Therefore are not required to be PCI DSS compliant.

SEC-6In the last 12 months did you have system outages or slowdowns that have had an impact on your ability to service your customers?

As an organisation, we are committed to providing 99.9% or higher uptime for our customers. While we have had some planned maintenance windows for system upgrade, we have had no unplanned outages involving 100% downtime as we follow a Multi-AZ architecture with redundancy. Having said that, there have been situations where some critical flows may have been impacted in specific scenarios. We have implemented robust observability mechanism including proactive monitoring, alerts and playbooks for quick resolution in such cases. We also follow that up with detailed RCAs to prevent such issues from happening again in future.

SEC-7Do you have a change management process in place to ensure the uptime of your service ?

We follow a comprehensive change management framework to ensure uptime and reliability. This includes detailed planning with rollback options, rigorous staging environment testing, formal approval workflows, and automated deployments to minimize downtime. Post-deployment monitoring and structured rollback processes further safeguard performance, reducing operational risks and maintaining service continuity.

SEC-8Do you have a Cyber Insurance Policy against cyber threats ?

Yes, coverage includes data breach, business interruption, regulatory fines, third-party liability, extortion, and incident expense, with regular reviews to ensure adequacy.

⚖️ Risk Management 11 questions
SEC-9Is there a defined risk management strategy? If yes, please indicate what are the main objectives?

Yes, we have a defined risk management strategy. The main objectives are to:

  • Identify and assess risks across security, technology, and operations
  • Mitigate risks through layered controls and safeguards
  • Align with regulatory and industry standards
  • Protect customer data and ensure business continuity
  • Monitor key risks and report at the executive level
SEC-10Was your institution subject to on site inspection by the regulators with regards to Risk Management?

As a SAAS platform, we are not directly subject to financial regulatory inspections. However, our risk management framework is independently audited through ISO 27001 surveillance audits, SOC2 Type II assessments, third party security teams for VAPT.

SEC-11What is the scope of operational risk management?
  • Technical risks: Security vulnerabilities, scalability issues, and performance concerns reviewed by the Architecture Review Board
  • Project risks: Tracked weekly through Project Review Meetings focusing on milestones, activities, and blockers
  • Platform stability: Managed through the "War Command Center"
  • Incident response: Robust incident response planning for security and operational disruptions
  • Deployment risks: Mitigated through blue-green deployment, automated failover, and rollback mechanisms
SEC-12Could you provide the list of your procedures in connection with the Management of Operational Risks?

Risk Identification: Conduct systematic and operational assessments, and staff report potential risks. Risk Analysis: Compile assessment results, risk-rate identified risks, and quantify impact and likelihood. Risk Evaluation: Benchmark computed risks against acceptable levels; threats above the acceptable level require mitigation. Risk Mitigation: Track risks to treatment, propose controls to reduce impact and likelihood, and take/monitor mitigation actions. Decisions on residual risk include acceptance, transfer, or adding controls. Monitoring and Review: Annually perform and learn from assessments, updating processes as needed. Reporting and Communication: Create and communicate risk assessment reports and mitigation measures to management and staff. Responsibilities: All staff are responsible for identifying, analyzing, evaluating, monitoring, and communicating risks.

SEC-13Is there a cartography / map of the operational risks?

We maintain an internal Issue Tracker that serves as our operational risk register. It documents risks, likelihood/impact scoring, control mappings, and mitigation actions. This register is reviewed quarterly and updated after audits, incidents, or significant changes.

SEC-14What is (are) the methodology(ies) (high level description) of the risk assessments?

The methodology for risk assessments involves:

  • Identification: Systematically listing all potential risks and threats to the organization's commitments.
  • Analysis & Quantification: For each identified threat, quantifying its potential impact (on a scale of 0-10) and the likelihood of its occurrence (as a number between 0-1). The net risk is then calculated as Impact multiplied by Likelihood.
  • Evaluation: Benchmarking the computed net risks against a predetermined acceptable risk level.
  • Mitigation Planning: For threats exceeding the acceptable risk level, proposing and designing activities and controls to reduce their impact and likelihood. A plan is created to implement these controls.
  • Residual Risk Assessment: After implementing mitigation strategies, recalculating the "Residual risk" to determine if it is acceptable, needs further controls, or requires risk transfer (e.g., insurance).
  • Reporting & Review: Creating a risk assessment report, communicating it to management and affected staff, and performing the assessment at least annually, incorporating learnings from previous assessments.
SEC-15Are they all registered or only above certain thresholds?

All incidents are logged. For reporting purposes, we classify them by severity (low, medium, high, critical). High/critical severity incidents trigger immediate escalation, while lower-severity ones are still tracked and analyzed for patterns.

SEC-16Is there an inventory of operational controls of your company?

We maintain an inventory of operational and security controls aligned with ISO 27001 and SOC2 trust principles. This includes technical, procedural, and organizational controls covering access management, change management, incident response, vendor risk, and business continuity.

SEC-17What is the methodology (high level description) of the assessment of the control effectiveness?

Controls are assessed using a risk-based approach:

  • Identify the control and associated risk.
  • Validate design effectiveness (is the control well defined?).
  • Test operating effectiveness (is it functioning as intended?) through sampling, system logs, or simulations.
  • Record results, assign residual risk rating, and define remediation actions if gaps are found.
SEC-18Is the 2nd line of defence reviewing / challenging the tests / assessments of the control effectiveness?

We actively engage with external auditors to independently review and validate the effectiveness of our controls

SEC-19With regards to the (potential) weaknesses / deficiencies identified through the different operational risk management processes / reviews, is there a process for following-up the remedial / mitigating actions defined for these weaknesses / deficiencies?

All identified weaknesses or deficiencies are logged in our Issue Tracker, assigned an owner, and tracked through to closure. Each action has a defined timeline, and progress is monitored during monthly reviews.

👥 Personnel & Training 5 questions
SEC-20Do you have an employee awareness program for information security threats ?

Yes, we have an active employee awareness program for information security threats. Over the past two years, our training initiatives have included comprehensive security awareness protocols that focus on various aspects of cybersecurity.

SEC-21Do you conduct background checks on employees who have access to sensitive systems or customer data?

Yes, all such employees undergo criminal, education, employment, and sometimes reference checks, especially for roles handling critical or sensitive systems.

SEC-22Do you have a process for managing and revoking access when an employee leaves the company?

All our internal tolols are accessed via SSO, and employee access to all systems is automatically revoked as soon as they are disabled in SSO.

SEC-23Do you have a dedicated internal Information Security Team handling operational aspects of IT security (firewalls, vulnerability management, authentication, …)?

We have a dedicated security and compliance team that manages governance, risk, access controls, and data protection. This team operates independently and reports directly to the CTO to ensure alignment with industry best practices and regulatory standards (ISO, SOC2, GDPR, etc.).

SEC-24Do you have dedicated internal team to manage your IT systems, network and applications ?

Yes, our dedicated internal team manages IT systems, networks, and applications, ensuring performance, security, and quick issue resolution.

🌐 Network & Perimeter 15 questions
SEC-25Do you have a Data Loss Prevention process in place to prevent the data loss/leak risks ?

We maintain a robust Data Loss Prevention (DLP) program to safeguard sensitive customer data throughout its lifecycle. Key measures include:

Regular backups: We have data replication across multi-availability zones, to prevent data loss in case of downtime. We further take backups for all production data at regular intervals.

Access Control: Strict user access based on least privilege and separation of duties.

Monitoring & Auditing: Continuous event monitoring and audit logs detect anomalies.

Regular Assessments: Annual policy reviews, third-party penetration testing, and vulnerability detection ensure ongoing security.

SEC-26Do you apply the latest market security standards/baselines for the hardening of your server, network devices, workstations and mobile devices ?

Yes, practices use CIS benchmarks, AWS best practices, OWASP, regular scans (Dependabot, SonarQube), container image scanning, and continuous patch cycles for comprehensive server and endpoint hardening.

SEC-27Do you ensure strict network separation between Production / Non-Production, and between Customer-facing / Internal networks ?

Yes, we have separate AWS/GCP accounts for production and non-production accounts. Further, we have stric role-based and least privilege access everywhere.

SEC-28Do you perform a strict control on incoming/outgoing network communications using a firewall and for example proxy servers ?

Yes, all web-facing access is protected with AWS WAF, security groups, NACLs to enforce traffic policy.

SEC-29Do you manage the monitoring / prevention of unauthorised devices connected to the network?

Unauthorized device filtering is achieved through security groups, IP whitelisting and AWS GuardDuty/alerting for suspicious access.

SEC-30If you have firewall to segment your network, are firewall rules subject to regular review?

Yes, all rules are reviewed at least quarterly (8 reviews in two years)

SEC-31Do you implement Intrusion Detection/Prevention Systems on all your critical network segments ?

We deploy Intrusion Detection and Prevention Systems (IDPS) across critical network segments. Integrated with AWS, our solution enables real-time monitoring, automated vulnerability assessments, and penetration testing. This proactive approach ensures continuous threat detection, rapid response, and strong protection of organizational data.

SEC-32Do you implement Web Application Firewalls (WAF) to safeguard your web-facing applications?

Yes, AWS WAF is enabled for all public endpoints

SEC-33Do you have Distributed Denial of Service (DDoS) protection in place?

Yes, AWS Shield are used for automatic DDoS protection

SEC-34How often are your DDoS mitigation capabilities tested?

Simulations are done twice yearly using third party vendors

SEC-35Does your organisation have an anti-malware protection installed on all servers and workstations?

Yes, endpoint and server anti-malware, container/Docker image scanning, email gateway scanning, zero-day behavioral detection, and scheduled weekly malware scans are enforced.

SEC-36How often are your anti-malware signatures/engines updated?

Real-time/daily signature updates, with quarterly engine updates, and continuous threat intelligence integration.

SEC-37Do you conduct an anti-malware scan on all the files exchanged with the customer? (incoming and outgoing)

Yes, all files are scanned pre-processing; infected files are quarantined, alerts generated, and Scan results integrated with threat intelligence feeds for preemptive action.

SEC-38Do you deploy patches on all your devices on regular basis ?

We follow a structured patch management process with regular device updates and periodic VAPT, supported by scheduled vulnerability scans. Detection tools and threat signatures are updated on an ongoing basis as per our vulnerability management policy. All updates follow a formal change management process to minimize disruptions, ensuring our systems remain secure, compliant, and aligned with best practices.

SEC-39Do you have a formally documented process to actively monitor your security vulnerabilities and an emergency patching process in place?

We actively monitor and remediate security vulnerabilities through real-time assessments, emergency patching, and regular VAPT. Using a risk-based model, we prioritize and apply patches promptly while continuously monitoring and logging security events. Our policies and procedures are reviewed annually to stay aligned with industry standards and compliance requirements.

🔍 Vulnerability & SDLC 8 questions
SEC-40Is the overall security of the systems and data regularly checked by penetration tests / red team / audit by an independent professional with appropriate skills?

Yes, biannual external VAPT, annual external security reviews for SOC/ISO compliance, ongoing CI/CD security testing, and full remediation/follow-ups—reports are available upon request.

SEC-41Has there been a security test (pentest, red team, audit, …) of the specific service recently ?

Yes, the most recent VAPT covered all applications; findings were fully remediated, with available reports demonstrating thorough follow-up and validation.

SEC-42Do you test the security aspects of all the elements of your IT framework before and after they are implemented ?

We enforce rigorous security testing across our IT framework, including pre- and post-deployment vulnerability assessments and penetration tests. Access authentication, AES-256 encryption for data at rest, and TLS 1.2 for data in transit are implemented. Our practices comply with standards such as ISO, SOC 2 Type 2, and ISO 27001. Real-time monitoring ensures anomalies are detected, and all components are securely managed in line with compliance requirements.

SEC-43Have you participated in Threat-Led Penetration Testing (TLPT)?

We actively engage in Threat-Led Penetration Testing (TLPT) as part of a robust cybersecurity framework. This includes activites like red-teaming to mimic attacker behaviours, regular vulnerability assessments and penetration tests, aligned with industry best practices, help identify and address potential system vulnerabilities proactively. These measures strengthen our defenses against malicious threats and demonstrate our commitment to maintaining the highest security standards.

SEC-44Do you follow a Secure Software Development Lifecycle (SSDLC)?

We integrate security throughout our SSDLC by performing early threat modeling, enforcing secure coding practices, and conducting regular VAPT. Strong access controls with MFA, data encryption at rest and in transit, and continuous monitoring further safeguard applications. An established incident response plan ensures swift remediation, maintaining secure and resilient software development.

SEC-45Do you have secure programming rules in place ?

Yes, OWASP-based secure coding, strict input validation, output encoding, session/authentication requirements, error handling and cryptographic rules, and checklists ensure all critical controls are implemented.

SEC-46Do you perform code review and remediation using automated tools (SAST, DAST, …)?

Yes we have automated checks as a part of our CI/CD pipeline using tools like SonarQube (static), CodeRabbit, Github dependabot etc to ensure to actively track security issues in development lifecycle.

SEC-47Do you perform security test on all the code you produce, in order to validate the key security control ?

Yes, unit, API, access control, logging, encryption, and integration security tests are performed on all code pre-release, with manual and automated review for full coverage.

🔑 Access & Identity 11 questions
SEC-48Will Customer manage the access right definition to the application ?

Yes, access can be managed by customers through SSO (Azure AD, Okta), admin APIs, RBAC portal, audit trails, automated provisioning, and delegated/group-based controls.

SEC-49Can Customer administrators manage password complexity ? (if applicable)

Yes, password complexity settings, expiry, session timeouts, and rotation periods are fully configurable by customer admins for all user types.

SEC-50Is a secure connection and authentication method in place to ensure credentials are not vulnerable to interception and replay?

Yes, TLS 1.2 certificate pinning, token-based authentication, session encryption/validation, and replay protections are enforced throughout. Session tokens and API keys are time-limited and can only be used once within their validity window.

SEC-51Have you implemented an account lockout policy, after x wrong passwords ?

Our security policy settings enforce these as a part of confugurations to setup and controls to the customers on how strict they want these actions to be

SEC-52Do you have a formal procedure for your internal user access management ?

Yes, documented access request/approval, RBAC assignment for specific roles.

All our internal tools are also behind SSO Authentications

SEC-53Do you apply access to data and systems following the “need to know” and “least privilege” principles?

Yes, by default the minimum access is provided to each user and a constant review of access is done to ensure if extra access added should be revoked.

SEC-54Do you have a user access provisioning / de-provisioning process in place and controlled? Is this process automated and logged ?

Yes, provisioning/deprovisioning is automated as all of our internal tools are behind SSO. The defualt access given follows the least priviledge but can be extended based on approval process. The actions are all logged, integrated with HR/onboarding/offboarding.

SEC-55Do you have a strong password policy in place ? Including password complexity, MFA, account lockout after x wrong passwords.

Yes, password policy requires min 12 characters, complexity, rotation (90 days).

SEC-56Do you have a specific strong supplier password policy in place? (if applicable)

We do not provide access to our systems to the suppliers.

SEC-57Do you have a PAM (Privileged Access Management) process in place to secure and monitor the access of your privileged users ?

Yes, our internal rools acts as a PAM for us to give visibility of these privilidges granted.

SEC-58Do you provide remote access technologies to your staff to access Customer assets (Data/Systems/Applications) ?

Yes, secure remote access enabled via VPN is present

📦 Data Protection & Privacy 14 questions
SEC-59In what countries is Customer Data stored or processed ?

The data is processed and stored in the designated deployment region for each customer.

SEC-60Do you store Customer data on your IT environment ?

Our IT Network is Cloud first. We store the data on the cloud only, customer data is securely stored with logical or physical separation, strict encryption, audit trails, and full compliance with residency/retention policies.

SEC-61Do you share data with your Customer ?

We exchange data securely with customers using methods such as REST APIs for real-time integration, SFTP for large datasets, and secured portals or encrypted emails for specific needs. All exchanges are protected with strong encryption (AES-256) for data at rest and in transit, ensuring confidentiality and compliance with industry standards.

SEC-62Do you have strong policy/procedures/security controls to protect Customer data stored at-rest ?

Yes, data-at-rest protection includes logical separation along with database segmentation. Employee access is controlled by RBAC along with MFA via VPN. An AES-256 encryption is in place for data access along with this access being restricted to DevOps Teams only.

SEC-63Do you have strong policy/procedures/security controls to protect Customer data in transit ?

Yes, data in transit is protected by TLS 1.2/1.3, certificate pinning, VPN, firewalls (WAF), IP whitelists.

Users access is restricted via RBAC and MFA. For all our tools we have SSO in place.

SEC-64Do you log and monitor all access to Customer assets in order to detect non-authorized access to Customer data ?

Yes, all access is logged with user agents along with IPs. Actions performed are logged with the Employee ID of the customer. Logs are retained for a defined period of 1 month for transient data and 12 months for retained actions.

Our synthetic alerts are setup for immediate detection of unauthorized actions or anomalies.

SEC-65Can you ensure data portability and secure deletion upon contract termination?

Yes, data can be exported in standard formats or via API, deleted securely from all locations, and all backups removed within 30 days in line with GDPR/compliance best practices.

SEC-66Do you have a documented data protection policy that defines appropriate data protection rules, roles and responsibilities, governance and resources and which is accepted and validated at the highest level of your company?

Yes, we have a data protection policy

SEC-67Have you assessed and documented the obligation - or not - to appoint a DPO (Data Protection Officer) in your organization?

Our organization has assessed the obligation to appoint a Data Protection Officer (DPO) in accordance with applicable privacy regulations and has appointed a qualified DPO to oversee compliance. The DPO is formally designated internally and serves as the point of contact for data protection authorities and customers. Where legally required, the DPO’s appointment has been notified to the competent Supervisory Authority.

SEC-68Are your employees who process the data regularly sensitized and / or trained about the protection of the personal data which they process?

Employees processing personal data are regularly trained and sensitized on secure data handling, confidentiality, and privacy best practices.

SEC-69Have you set up a register which documents (in accordance with article 30 of the GDPR) all the categories of processing activity that you carry out on behalf of your Customers (when they are qualified as a Data Controller )?

We maintain an inventory (records of processing activities) of categories of personal information collected along with its usage, sources and specific purposes for collection (including GDPR)

SEC-70Have you defined a process to periodically (at least annually) review and approve the register of processing activities that you carry out as a data processor, in order to ensure the completeness and relevance of the register?

The record is reviewed annually

SEC-71Have you implemented measures to ensure that your subcontractors offer the same level of guarantees as you in regard to data protection?

Shipsy requires all subprocessors to meet equivalent data-protection guarantees via contractual flow-downs, pre-engagement due diligence, ongoing risk assessments, audit rights and enforceable deletion/return obligations as set out in our Vendor Management Policy

SEC-72Is the management of your organisation fully aware of the residual risks and formally accepts them?

There is a periodic review of risks by management

🚨 Incident Response & DR 8 questions
SEC-73Do you have a continuous process to detect security incidents?

Yes, 24/7 incident monitoring via likes of AWS GuardDuty/Security Hub and SIEM, with alerts to a security team and escalation matrix.

SEC-74Do you store security logs on a central and secured place (like a SIEM) to provide effective protection of security and operational logs ?

Yes, logs are centrally stored via ELK, encrypted at rest, made immutable, and access is strictly controlled and audited.

SEC-75Can you attach all the logs and events to individuals in your organisation ? (in this case nominative access should be used for all actions, including privileged access for example)

Yes, every action is tied to an individual (no shared accounts), all API/privileged accesses are logged to user/entity, and session and audit trails enable complete forensics and compliance.

SEC-76Can your organisation ensure early detection of a cyber-attack ?

Yes, real-time AWS GuardDuty, ML-based anomaly detection, alerting, network and behavioral analysis, and a 24/7 monitoring systems with predefined alerts help detection and escalation.

SEC-77Has the log management procedure been audited in the last 2 years?

Yes, log management is covered in regular internal/external audits for SOC 2/ISO certifications, with findings addressed, verified by third parties, and audit summaries available for review.

SEC-78Do you have a cyber incident response plan (IRP) ?

Yes. We maintain a documented cyber incident management process covering detection, containment, investigation, remediation, and communication. Roles and escalation paths are clearly defined. The process is reviewed and updated regularly, and we conduct simulations at least annually (with ad-hoc tabletop drills for specific scenarios) to ensure preparedness.

SEC-79Do you have capability to conduct forensics investigations (internally of through a third party) ?

Yes. In the event of a security incident requiring forensic investigation, our security and engineering teams perform the initial analysis (log review, system tracing, and evidence collection). For deep forensic expertise, we have the ability to engage trusted third-party specialists to conduct detailed investigations. This ensures that incidents are handled thoroughly and in accordance with industry best practices.

SEC-80Have you encountered any major security incidents in the last 2 years ? (A major security Incident is an security incident with an high impact on the organisation, the reputation or with high financial losses)

No major breaches occurred; minor events were handled through the incident plan, RCA, and regular improvements, with transparency and documentation available for review.

🤝 Third Parties & Suppliers 9 questions
SEC-81Do you have a formal policy or procedure for managing information security risks linked to your third-party suppliers?

Yes we have a Vendor Management Policy which has provisions of Risks and Contractual Liabilities on Information Security.

SEC-82Do you use subcontractors for any critical or important functions (CIF)?

Yes, all strategic subcontractors (AWS, GCP, Azure, CloudFlare, payment partners) are certified to SOC 2/ISO/PCI DSS/CREST standards and undergo regular security review.

SEC-83How do you perform due diligence on your own suppliers and subcontractors?

Due diligence involves security questionnaires, certifications, reference checks, stability assessment, DPAs, regular audits, monitoring, and performance reviews.

SEC-84Do you require your sub-contractors to comply with the same security standards and obligations as your own organisation?

Yes, all contracts enforce equivalent security, data protection, compliance, audit, certification and incident response requirements for all subcontractors.

SEC-85Do you use Third-Parties (sub-processors) to provide aspects of the service?

Yes, main subprocessors: AWS/GCP/Azure for infra, MongoDB Atlas (DB), CloudFlare (CDN/DDoS), SendGrid/Twilio (communication), and accredited payment gateways. All subprocessors are under data processing agreements.

SEC-86Do you conduct background checks or compliance screenings on suppliers/third-parties who are going to access sensitive systems or customer data?

Yes, all suppliers undergo certification, compliance, legal, financial, and background vetting with ongoing monitoring as required by risk.

SEC-87Do your suppliers process or store data outside the EU/EEA?

Yes, compliance is strictly maintained via Standard Contractual Clauses, adequacy, DPAs, regular audits, residency options, location transparency, and customer consent when needed.

SEC-88Do your suppliers have an incident response and breach notification process that is aligned with your own requirements?

Yes, some supplier contracts require notification within 24 hours but not all. We also use very limited Suppliers.

SEC-89Have you had any significant security incidents or breaches involving third parties in the last 24 months?

No significant third-party incidents; proactive monitoring, regular assessment, rapid response, incident coordination, and lessons learned practices prevent and mitigate issues.

🔄 Business Continuity 14 questions
SEC-90Organisation ISO 22301 certified :

SOC 2 Type 2 and ISO 27001 certifications are maintained.

SEC-91Documented DRP :

Our solution leverages a Multi-AZ setup, providing built-in redundancy and high availability. This design supports our disaster recovery strategy by ensuring critical systems and data remain operational during infrastructure failures, minimizing downtime and maintaining business continuity.

SEC-92BCP documented :

All of our application running in Multi-AZ which offers business continuity even if the entire data center goes down.

SEC-93BCP covers the following threats :

Our BCP addresses critical threats including building inaccessibility or destruction, IT infrastructure failure, cyber-attacks, pandemics, and key provider failures. It ensures continuity of operations and rapid recovery to minimize business disruption.

SEC-94Describe for all the above threats your business continuity strategy (rescue site in case of loss of main site; back-up / restore strategy for data and IT systems; teleworking infrastructure; redundancy of key providers; etc.)

Our BCP ensures resilience against physical, technical, and operational threats. Critical systems and data are backed up and replicated to a DR site in AWS Stockholm, supporting rapid failover. Teleworking infrastructure allows continuity during building inaccessibility or pandemics, and redundant key providers mitigate service disruptions. Regular backups, tested restore procedures, and security controls ensure minimal downtime and sustained operations under all major threat scenarios.

SEC-95Resources available to the organization in a continuity scenario as part of the standard offerings :

We assign a dedicated Account Manager to each client, serving as the primary contact for technical or operational issues and ensuring timely resolution and coordinated support.

SEC-96Additional service offerings available to assist the organization in a disaster scenario (e.g. recovery support services), and associated costs :

Our platform includes comprehensive disaster recovery capabilities with enterprise-grade support services. The built-in disaster recovery features include active-active setup with read replicas across multiple availability zones, automated failover mechanisms, redundant backups in geographically separate locations, and regular backup testing protocols. For recovery support, we provide a 3-tier support structure with named contacts at each level - Level 1 Help Desk for initial response, and Level 2/3 direct access to Support Manager and VP Growth for escalations. Additional services include regular disaster recovery testing to ensure systems are ready when needed, zero data loss architecture with real-time replication and journaling, and multi-tier redundancy across application, database, and infrastructure layers. Associated costs for these services would depend on the specific deployment model chosen and can be discussed in detail based on specific deployment requirements.

SEC-97Incident Mangement Plan documented including an escalation process, key contacts and reporting timescales in the event of an incident :

Yes. Our documented Incident Management Plan includes a clear escalation process, designated key contacts, and defined reporting timescales to ensure timely response and resolution of incidents, minimizing business impact.

SEC-98Inform Client if an incident negatively impacts the continuity of the service provided to Client, by which means and timeframe :

If an incident negatively impacts the continuity of service provided to a client, we inform the client promptly via email, phone, or designated communication channels. Notification is provided as soon as the incident is identified and assessed, with regular updates on remediation progress until resolution. This ensures transparency and enables clients to take any necessary interim actions.

SEC-99Governance organized (responsibilities; resources in charge) :

Our governance framework assigns clear responsibilities across security, compliance, operations, and service delivery, with dedicated teams and an Account Manager overseeing each client.

SEC-100Subject to regular controls and audits by internal or external authorities (which ones) :

Our operations and systems undergo regular internal and external audits, including ISO 27001 and SOC 2 to ensure security, compliance, and operational integrity.

SEC-101GDPR processing services and systems resilient or included in your Business Continuity Management System (BCMS) :

Yes. All systems and services involved in GDPR-related data processing are designed to be highly resilient and are fully included within our Business Continuity Management System (BCMS). This ensures that personal data remains protected, accessible, and recoverable in the event of disruptions, while maintaining compliance with GDPR requirements.

SEC-102Client has options to reduce their current maximum downtime :

Clients can reduce their maximum downtime by leveraging Multi-AZ deployments, real-time data replication, and dedicated support services. These features enhance system resilience, improve failover capabilities, and accelerate recovery in the event of disruptions.

SEC-103Client has options to reduce their current maximum data loss :

Clients can reduce potential data loss by leveraging real-time data replication, frequent automated backups, and Multi-AZ deployments. These measures ensure that critical data remains protected and recoverable in the event of system failures or disruptions. Optional configurations can also be implemented to further minimize recovery point objectives (RPO) based on specific operational requirements.

📊 Data Quality & Governance 8 questions
SEC-104Company developped a formal data governance policy (framework, roles and responsibilites, data quality procedures):

We maintain a formal Data Governance Policy covering the framework, defined roles and responsibilities, and data quality procedures to ensure secure, accurate, and compliant data management.

SEC-105Put in place regular data quality controls :

We have regular data quality controls in place, including automated validation, periodic audits, and monitoring, to ensure accuracy, consistency, and compliance.

SEC-106Cover all relevant data quality dimensions (accuracy, completeness, consistency, timeliness, uniqueness, validity) :

Our controls cover all key data quality dimensions: accuracy, completeness, consistency, timeliness, uniqueness, and validity.

SEC-107Execution and evaluation of their results (ex.: quality thresholds):

We apply thresholds and automated checks to monitor data quality. Results are reviewed regularly, with corrective actions initiated when thresholds are breached.

SEC-108Data quality issues monitored:

Data quality issues are centrally tracked through established incident and defect management processes, with remediation assigned to data owners.

SEC-109Produce a regular reporting on data quality:

We generate internal reports and dashboards on data quality metrics and share relevant insights with stakeholders as needed.

SEC-110Put in place a formal process which alerts Clients in case of a data quality issue concerning the data provided to Client:

If a data quality issue impacts client deliverables, clients are notified promptly through our incident communication process, along with remediation plans.

SEC-111Put in place a formal process which alerts Clients in case of technical changes:

A formal change management process is in place. Clients are notified of technical or structural changes in advance through release notes, communications, or direct updates.

99.9%
Uptime SLA
5B+
Shipments / Year
100M+
API Events / Day
270M+
Webhooks / Day
☁️

Cloud Infrastructure

AWS (Default) · GCP · Azure · On-Premise
  • AWS is the primary deployment platform — deepest expertise, best uptime, fastest go-live
  • GCP available as fallback; on-premise supported for qualifying enterprise deals
  • Multi-AZ active-active — compute + storage redundancy within region
  • Terraform IaC: spin up new infrastructure in alternate region in minutes
  • Docker images scanned via AWS ECR; AWS Fargate handles OS-level security patching
📡

Monitoring & Alerting

New Relic · CloudWatch · War Command Center
  • 24/7 real-time monitoring: New Relic APM + CloudWatch + OpenSearch
  • ZenDuty on-call paging + Slack + email; Public Statuspage for customers
  • War Command Center: emergency playbook — Block APIs, Caching Controls, Read Replica failover, Stop Non-Critical Load, Pre-Defined Response Templates
  • Proactive monitoring before issues reach customers; shift-wise standups for critical issues

Integration Scale

100M+ Events/Day · 5B+ Shipments/Year · 8 Methods
  • 100M+ API events/day · 270M+ webhooks/day · 90M+ async messages/day
  • 8 integration methods: REST API, Webhooks, SDK, ETL Pipelines, File-based, Integration Marketplace, EDI, SFTP
  • AI-powered Low-Code Integration Platform: Handlebar templates, JSON/XML, Workflow automation
  • ERP-ready out of box: SAP S/4HANA, Oracle Fusion Cloud, Microsoft Dynamics 365, NetSuite, Tally, Zoho
🛡️

Network Defences

WAF · Shield · GuardDuty · SIEM
  • AWS WAF + GCP Armor — layer 7 filtering
  • AWS Shield — DDoS mitigation
  • GuardDuty ML-based threat detection (IDS)
  • ELK Stack SIEM — centralised security analytics
  • VPC network isolation per deployment
🔐

Encryption

AES-256 · TLS 1.2 · Vault
  • AES-256 for all data at rest (managed DB + storage layers)
  • TLS 1.2 minimum for all data in transit — HTTPS enforced
  • Certificates from trusted providers on all public endpoints
  • HashiCorp Vault — automated key management and rotation
  • Laptop full-disk encryption enforced for all staff
🔄

Resilience & DR

RPO 5 min · RTO 25 min
  • Active-active Multi-AZ: compute + storage redundancy within region
  • RPO: 5 minutes · RTO: 25 minutes
  • Blue-Green deployment: zero-downtime releases, instant rollback on anomaly detection
  • Rolling deployments ensure system stays operational during updates
  • Scheduled maintenance windows with advance client communication + release notes

Technology Stack

Core security and infrastructure components
ComponentTechnologyNotes
Container OrchestrationKubernetesECSManaged container workloads
Infrastructure as CodeTerraformReproducible, auditable provisioning
Web Application FirewallAWS WAFGCP ArmorL7 filtering, protocol anomaly detection
DDoS ProtectionAWS ShieldNetwork and transport layer protection
Threat Detection (IDS)GuardDutySecurity HubML-based anomaly and threat detection
SIEMELK StackElasticsearch, Logstash, Kibana
APM / MonitoringNew RelicCloudWatchOpenSearch24/7 real-time observability
Key ManagementHashiCorp VaultAutomated rotation, strict access control
CDNCloudCDNEdge caching and DDoS mitigation layer
SAST / Code QualitySonarQubeCodeRabbitAI-powered PR review + security hotspot detection in every CI/CD pipeline
E2E Test AutomationPlaywrightAppiumWeb (Playwright) + Mobile (Appium) automated testing; session recording + replay
Test ManagementTestmoTest case repository, CI/CD integration, Slack reporting for stakeholders
Deployment StrategyBlue-GreenRollingZero-downtime releases; automated failover; instant rollback on green metric monitoring
Container SecurityAWS ECRAWS FargateDocker image scanning via ECR; Fargate handles OS-level security patching automatically
Dependency ScanningDependabotAutomated vulnerability alerting
On-call AlertingZenDuty24/7 paging + Slack + email integration
Compliance MonitoringSprintoContinuous control monitoring & evidence
Change ManagementJIRAAll development requirements (Project / Enhancement / Feature) logged and tracked
Primary DatabasePostgreSQLMaster/slave replication; dedicated instances for high-volume customers
Data WarehouseAmazon RedshiftNear real-time streaming from transactional systems; retains data up to 2 years
🔐

Encryption Standards

AES-256 · TLS 1.2 · Vault
  • AES-256 encryption for all data at rest
  • TLS 1.2 minimum for all data in transit — HTTPS enforced
  • PII encrypted and stored in a separate, dedicated database — isolated from main application DB
  • PII hidden from analytics logs and views by default
  • HashiCorp Vault for key management and rotation; IP whitelisting on DB access
🌍

Data Residency

Customer-Designated Region
  • Customer selects cloud provider and deployment region
  • AWS, GCP, Azure, or on-premise supported globally
  • SCCs govern any necessary cross-border transfers
  • DTIAs conducted per EDPB guidance
  • Sub-processor locations maintained and disclosed
📁

Retention & Deletion

7-Day Backups · 1-Year Default
  • Daily full backups, 7-day retention minimum
  • Transactional data retained up to 1 year; Data Warehouse (Redshift) retains up to 2 years
  • Deletion requests authenticated and processed
  • Anonymisation considered before deletion where appropriate
  • Policy documentation retained for minimum 6 years
⚖️

GDPR Compliance

Processor Model · Privacy by Design
  • Data erasure (Art. 17) supported per DPA scope
  • Data portability via API or standard formats
  • Access requests (Art. 15) via defined workflow
  • Privacy Impact Assessments for new products and changes
  • DPA and SCCs available on request
💾

Backup & Recovery

RPO 5 min · Multi-AZ Replication
  • Daily automated backups, 7-day minimum retention
  • Backups AES-256 encrypted in geographically separate AZs
  • Continuous real-time replication across Multi-AZ
  • Backup restoration tested and documented annually
  • RPO: 5 minutes · RTO: 25 minutes
🔑

Access Control

RBAC · MFA · Least Privilege
  • RBAC with location-hierarchy-based visibility — role-based access to specific functions and data
  • SSO with SAML and OAuth 2.0; MFA using TOTP-based solutions
  • Session Timeout enforced; Token Rotation + CAPTCHA implementation
  • Auth Key Restriction on specific APIs; limiting devices to single-user access
  • Vault-based DB access; IAM + MFA + IP Whitelisting on database access
  • Approval-based flows for sensitive actions across the platform

Data Classification Framework

How Shipsy categorises and protects all data
ClassificationDescriptionExamplesProtection Level
PublicNo special handling; disclosure causes no harmMarketing, press releases, career pagesStandard
Company InternalAll staff access; not for external partiesHR policies, operational proceduresAccess-controlled
Company ConfidentialPre-authorised staff onlyEmployee data, legal documents, roadmapsStrictly restricted
Customer ConfidentialHighest protection — data entrusted by customersCustomer PII, shipment data, account infoMaximum — encrypted, access-logged, controlled

Personal Data Processing

Categories of personal data processed as part of the logistics platform
Data TypePurposeRetention
Consignee contact detailsDelivery coordination and notificationsDuration of contract + 1 year
Driver identity & locationRoute assignment, real-time trackingDuration of contract + 1 year
Shipment metadataTracking, analytics, proof-of-deliveryDuration of contract + 1 year
Customer admin accountsPlatform access and audit trailDuration of account + 1 year
Support correspondenceIssue resolution, audit logging2 years
OTP / SMS communicationsSecure delivery confirmation30 days

Infrastructure Sub-processors

Core cloud providers hosting and processing customer data
Sub-processorPurposeData ProcessedCertifications
Amazon Web Services (AWS)Cloud infrastructure, compute, storage, networkingAll customer data (primary hosting)SOC 2 Type II, ISO 27001, PCI DSS
Google Cloud Platform (GCP)Cloud infrastructure (select deployments)Customer data per deployment regionSOC 2 Type II, ISO 27001, PCI DSS
Microsoft AzureCloud infrastructure (select deployments)Customer data per deployment regionSOC 2 Type II, ISO 27001, PCI DSS
MongoDB AtlasManaged database serviceApplication data, metadataSOC 2 Type II, ISO 27001
All sub-processors are bound by Data Processing Agreements (DPAs). Customer selects cloud provider and deployment region. Full sub-processor list available on request.