Built for enterprises
that cannot afford
to compromise.
Shipsy is a Gartner-recognized, AI-native logistics platform trusted by 270+ global enterprises across 30+ countries. Every control, certification, and practice on this page reflects actual Shipsy policy — audited, documented, and available for review. The platform processes 5+ billion shipments per year across 270+ enterprises in 30+ countries.
Formal ISMS
ISO 27001-aligned ISMS. Dedicated ISO. Annual risk assessments. Policies reviewed at least annually. Reported to CTO.
Third-Party Audited
SOC 2 Type II certified. ISO 27001 via BSI. Biannual external VAPT. Annual TLPT red-team. Reports under NDA.
Always On
99.9% uptime SLA. Active-active Multi-AZ. RPO 5 min, RTO 25 min. Daily backups. DR tested annually.
Privacy by Design
GDPR compliant. SCCs & DPA available. DTIAs conducted. Data stays in your chosen region.
Deploy Anywhere, Your Rules
Cloud-agnostic on AWS, GCP, or Azure. Customer selects cloud provider and deployment region globally. On-premise also supported. Zero vendor lock-in.
Audit-Ready at Any Time
SOC 2 Type II report, ISO 27001 certificate, VAPT summaries, and completed DDQs available under NDA. Security briefings available for enterprise procurement teams.
Enterprise-Scale Integration
8 integration methods: REST APIs, Webhooks, SDK, ETL Pipelines, File-based (CSV/Excel), Integration Marketplace, EDI, SFTP. ERP-ready: SAP S/4HANA, Oracle Fusion, Microsoft Dynamics 365, NetSuite. 100M+ API events/day processed reliably.
Defence-in-Depth
AWS WAF + GCP Armor, Shield DDoS, GuardDuty ML threat detection, ELK SIEM, SonarQube SAST, CodeRabbit, and Dependabot — all active, all the time.
Contractual Commitments
Data Processing Agreements with Standard Contractual Clauses. Custom DPA terms negotiable for enterprise. Sub-processor list maintained. NDA on all disclosures.
Full Transparency
Real-time public Statuspage. Proactive incident communication. 72-hour breach notification. No security-through-obscurity. Everything documented.
🏢 Company & Security Structure
- Dedicated CISO / security function reporting directly to CTO
- Information Security Officer (ISO) owns all ISMS controls
- All staff sign NDAs with post-employment confidentiality clauses
- Security awareness training at onboarding + annually for all staff
- Background checks on all prospective employees (where legally permitted)
🏅 Certifications & Compliance
- SOC 2 Type II — Certified (report available under NDA)
- ISO 27001:2022 — Certified via BSI (British Standards Institution)
- GDPR — Compliant; DPA + SCCs available
- Cyber Insurance — Active policy maintained
🛡️ Security Testing Calendar
- Continuous — SonarQube + CodeRabbit SAST, 24/7 SIEM, vulnerability scanning, Playwright + Appium E2E tests in CI/CD
- Quarterly — Firewall rule reviews, production access rights reviews, Docker image scanning via AWS ECR
- Biannual — External VAPT (PII Encryption tested), DDoS simulation exercises
- Annual — TLPT / red-team exercises, IRP tabletop drills, DR failover tests (Multi-AZ and Multi-Region)
🚨 Incident Response
- Documented IRP with escalation matrix and named roles
- Four severity levels: Low / Medium / High / Critical with defined triggers
- Supervisory authority notified within 72 hours
- Mandatory RCA for all High / Critical events
- No major security breaches reported
Certifications & Audits
Shipsy undergoes rigorous third-party audits and maintains industry-recognized certifications to validate our security controls across all layers of the stack.
SOC 2 Type II
Independent audit of security, availability, processing integrity, confidentiality, and privacy controls over a sustained observation period.
ISO 27001:2022
International standard for Information Security Management Systems (ISMS), demonstrating systematic management of information security risks.
GDPR Compliance
Full compliance with EU GDPR. DPA and Standard Contractual Clauses available. Privacy by Design embedded in all product development.
Yes, our organisation has a dedicated Information Security function led by a Chief Information Security Officer (CISO). The CISO is responsible for overseeing all aspects of information security management, including policy development, risk management, compliance, incident response, and continuous monitoring of security controls across our infrastructure.
Yes, we have a defined Information Security Strategy. Our strategy encompasses a comprehensive set of policies, procedures, and technical measures aimed at protecting information assets and ensuring compliance with industry standards. These measures include robust access controls, data encryption, and regular security assessments such as vulnerability assessments and penetration testing (VAPT). We maintain policies for data security and privacy lifecycle management, infrastructure and virtualization security, and identity and access management. Our platform is also compliant with security standards like ISO, and SOC 2, reinforcing our commitment to maintaining a high-security posture.
Yes, SOC 2 Type 2 and ISO 27001 certifications are maintained. Reports and VAPT results are updated annually and available on request, reflecting global best practice adherence
We review the information security policy every 3 months
We do not store or process any end user confidential Credit card or banking account information within Shipsy's systems. Instead rely on PCI DSS-compliant third parties (like Stripe, Razorpay, PayPal, Adyen, etc.) to handle payments end-to-end. Therefore are not required to be PCI DSS compliant.
As an organisation, we are committed to providing 99.9% or higher uptime for our customers. While we have had some planned maintenance windows for system upgrade, we have had no unplanned outages involving 100% downtime as we follow a Multi-AZ architecture with redundancy. Having said that, there have been situations where some critical flows may have been impacted in specific scenarios. We have implemented robust observability mechanism including proactive monitoring, alerts and playbooks for quick resolution in such cases. We also follow that up with detailed RCAs to prevent such issues from happening again in future.
We follow a comprehensive change management framework to ensure uptime and reliability. This includes detailed planning with rollback options, rigorous staging environment testing, formal approval workflows, and automated deployments to minimize downtime. Post-deployment monitoring and structured rollback processes further safeguard performance, reducing operational risks and maintaining service continuity.
Yes, coverage includes data breach, business interruption, regulatory fines, third-party liability, extortion, and incident expense, with regular reviews to ensure adequacy.
Yes, we have a defined risk management strategy. The main objectives are to:
- Identify and assess risks across security, technology, and operations
- Mitigate risks through layered controls and safeguards
- Align with regulatory and industry standards
- Protect customer data and ensure business continuity
- Monitor key risks and report at the executive level
As a SAAS platform, we are not directly subject to financial regulatory inspections. However, our risk management framework is independently audited through ISO 27001 surveillance audits, SOC2 Type II assessments, third party security teams for VAPT.
- Technical risks: Security vulnerabilities, scalability issues, and performance concerns reviewed by the Architecture Review Board
- Project risks: Tracked weekly through Project Review Meetings focusing on milestones, activities, and blockers
- Platform stability: Managed through the "War Command Center"
- Incident response: Robust incident response planning for security and operational disruptions
- Deployment risks: Mitigated through blue-green deployment, automated failover, and rollback mechanisms
Risk Identification: Conduct systematic and operational assessments, and staff report potential risks. Risk Analysis: Compile assessment results, risk-rate identified risks, and quantify impact and likelihood. Risk Evaluation: Benchmark computed risks against acceptable levels; threats above the acceptable level require mitigation. Risk Mitigation: Track risks to treatment, propose controls to reduce impact and likelihood, and take/monitor mitigation actions. Decisions on residual risk include acceptance, transfer, or adding controls. Monitoring and Review: Annually perform and learn from assessments, updating processes as needed. Reporting and Communication: Create and communicate risk assessment reports and mitigation measures to management and staff. Responsibilities: All staff are responsible for identifying, analyzing, evaluating, monitoring, and communicating risks.
We maintain an internal Issue Tracker that serves as our operational risk register. It documents risks, likelihood/impact scoring, control mappings, and mitigation actions. This register is reviewed quarterly and updated after audits, incidents, or significant changes.
The methodology for risk assessments involves:
- Identification: Systematically listing all potential risks and threats to the organization's commitments.
- Analysis & Quantification: For each identified threat, quantifying its potential impact (on a scale of 0-10) and the likelihood of its occurrence (as a number between 0-1). The net risk is then calculated as Impact multiplied by Likelihood.
- Evaluation: Benchmarking the computed net risks against a predetermined acceptable risk level.
- Mitigation Planning: For threats exceeding the acceptable risk level, proposing and designing activities and controls to reduce their impact and likelihood. A plan is created to implement these controls.
- Residual Risk Assessment: After implementing mitigation strategies, recalculating the "Residual risk" to determine if it is acceptable, needs further controls, or requires risk transfer (e.g., insurance).
- Reporting & Review: Creating a risk assessment report, communicating it to management and affected staff, and performing the assessment at least annually, incorporating learnings from previous assessments.
All incidents are logged. For reporting purposes, we classify them by severity (low, medium, high, critical). High/critical severity incidents trigger immediate escalation, while lower-severity ones are still tracked and analyzed for patterns.
We maintain an inventory of operational and security controls aligned with ISO 27001 and SOC2 trust principles. This includes technical, procedural, and organizational controls covering access management, change management, incident response, vendor risk, and business continuity.
Controls are assessed using a risk-based approach:
- Identify the control and associated risk.
- Validate design effectiveness (is the control well defined?).
- Test operating effectiveness (is it functioning as intended?) through sampling, system logs, or simulations.
- Record results, assign residual risk rating, and define remediation actions if gaps are found.
We actively engage with external auditors to independently review and validate the effectiveness of our controls
All identified weaknesses or deficiencies are logged in our Issue Tracker, assigned an owner, and tracked through to closure. Each action has a defined timeline, and progress is monitored during monthly reviews.
Yes, we have an active employee awareness program for information security threats. Over the past two years, our training initiatives have included comprehensive security awareness protocols that focus on various aspects of cybersecurity.
Yes, all such employees undergo criminal, education, employment, and sometimes reference checks, especially for roles handling critical or sensitive systems.
All our internal tolols are accessed via SSO, and employee access to all systems is automatically revoked as soon as they are disabled in SSO.
We have a dedicated security and compliance team that manages governance, risk, access controls, and data protection. This team operates independently and reports directly to the CTO to ensure alignment with industry best practices and regulatory standards (ISO, SOC2, GDPR, etc.).
Yes, our dedicated internal team manages IT systems, networks, and applications, ensuring performance, security, and quick issue resolution.
We maintain a robust Data Loss Prevention (DLP) program to safeguard sensitive customer data throughout its lifecycle. Key measures include:
Regular backups: We have data replication across multi-availability zones, to prevent data loss in case of downtime. We further take backups for all production data at regular intervals.
Access Control: Strict user access based on least privilege and separation of duties.
Monitoring & Auditing: Continuous event monitoring and audit logs detect anomalies.
Regular Assessments: Annual policy reviews, third-party penetration testing, and vulnerability detection ensure ongoing security.
Yes, practices use CIS benchmarks, AWS best practices, OWASP, regular scans (Dependabot, SonarQube), container image scanning, and continuous patch cycles for comprehensive server and endpoint hardening.
Yes, we have separate AWS/GCP accounts for production and non-production accounts. Further, we have stric role-based and least privilege access everywhere.
Yes, all web-facing access is protected with AWS WAF, security groups, NACLs to enforce traffic policy.
Unauthorized device filtering is achieved through security groups, IP whitelisting and AWS GuardDuty/alerting for suspicious access.
Yes, all rules are reviewed at least quarterly (8 reviews in two years)
We deploy Intrusion Detection and Prevention Systems (IDPS) across critical network segments. Integrated with AWS, our solution enables real-time monitoring, automated vulnerability assessments, and penetration testing. This proactive approach ensures continuous threat detection, rapid response, and strong protection of organizational data.
Yes, AWS WAF is enabled for all public endpoints
Yes, AWS Shield are used for automatic DDoS protection
Simulations are done twice yearly using third party vendors
Yes, endpoint and server anti-malware, container/Docker image scanning, email gateway scanning, zero-day behavioral detection, and scheduled weekly malware scans are enforced.
Real-time/daily signature updates, with quarterly engine updates, and continuous threat intelligence integration.
Yes, all files are scanned pre-processing; infected files are quarantined, alerts generated, and Scan results integrated with threat intelligence feeds for preemptive action.
We follow a structured patch management process with regular device updates and periodic VAPT, supported by scheduled vulnerability scans. Detection tools and threat signatures are updated on an ongoing basis as per our vulnerability management policy. All updates follow a formal change management process to minimize disruptions, ensuring our systems remain secure, compliant, and aligned with best practices.
We actively monitor and remediate security vulnerabilities through real-time assessments, emergency patching, and regular VAPT. Using a risk-based model, we prioritize and apply patches promptly while continuously monitoring and logging security events. Our policies and procedures are reviewed annually to stay aligned with industry standards and compliance requirements.
Yes, biannual external VAPT, annual external security reviews for SOC/ISO compliance, ongoing CI/CD security testing, and full remediation/follow-ups—reports are available upon request.
Yes, the most recent VAPT covered all applications; findings were fully remediated, with available reports demonstrating thorough follow-up and validation.
We enforce rigorous security testing across our IT framework, including pre- and post-deployment vulnerability assessments and penetration tests. Access authentication, AES-256 encryption for data at rest, and TLS 1.2 for data in transit are implemented. Our practices comply with standards such as ISO, SOC 2 Type 2, and ISO 27001. Real-time monitoring ensures anomalies are detected, and all components are securely managed in line with compliance requirements.
We actively engage in Threat-Led Penetration Testing (TLPT) as part of a robust cybersecurity framework. This includes activites like red-teaming to mimic attacker behaviours, regular vulnerability assessments and penetration tests, aligned with industry best practices, help identify and address potential system vulnerabilities proactively. These measures strengthen our defenses against malicious threats and demonstrate our commitment to maintaining the highest security standards.
We integrate security throughout our SSDLC by performing early threat modeling, enforcing secure coding practices, and conducting regular VAPT. Strong access controls with MFA, data encryption at rest and in transit, and continuous monitoring further safeguard applications. An established incident response plan ensures swift remediation, maintaining secure and resilient software development.
Yes, OWASP-based secure coding, strict input validation, output encoding, session/authentication requirements, error handling and cryptographic rules, and checklists ensure all critical controls are implemented.
Yes we have automated checks as a part of our CI/CD pipeline using tools like SonarQube (static), CodeRabbit, Github dependabot etc to ensure to actively track security issues in development lifecycle.
Yes, unit, API, access control, logging, encryption, and integration security tests are performed on all code pre-release, with manual and automated review for full coverage.
Yes, access can be managed by customers through SSO (Azure AD, Okta), admin APIs, RBAC portal, audit trails, automated provisioning, and delegated/group-based controls.
Yes, password complexity settings, expiry, session timeouts, and rotation periods are fully configurable by customer admins for all user types.
Yes, TLS 1.2 certificate pinning, token-based authentication, session encryption/validation, and replay protections are enforced throughout. Session tokens and API keys are time-limited and can only be used once within their validity window.
Our security policy settings enforce these as a part of confugurations to setup and controls to the customers on how strict they want these actions to be
Yes, documented access request/approval, RBAC assignment for specific roles.
All our internal tools are also behind SSO Authentications
Yes, by default the minimum access is provided to each user and a constant review of access is done to ensure if extra access added should be revoked.
Yes, provisioning/deprovisioning is automated as all of our internal tools are behind SSO. The defualt access given follows the least priviledge but can be extended based on approval process. The actions are all logged, integrated with HR/onboarding/offboarding.
Yes, password policy requires min 12 characters, complexity, rotation (90 days).
We do not provide access to our systems to the suppliers.
Yes, our internal rools acts as a PAM for us to give visibility of these privilidges granted.
Yes, secure remote access enabled via VPN is present
The data is processed and stored in the designated deployment region for each customer.
Our IT Network is Cloud first. We store the data on the cloud only, customer data is securely stored with logical or physical separation, strict encryption, audit trails, and full compliance with residency/retention policies.
We exchange data securely with customers using methods such as REST APIs for real-time integration, SFTP for large datasets, and secured portals or encrypted emails for specific needs. All exchanges are protected with strong encryption (AES-256) for data at rest and in transit, ensuring confidentiality and compliance with industry standards.
Yes, data-at-rest protection includes logical separation along with database segmentation. Employee access is controlled by RBAC along with MFA via VPN. An AES-256 encryption is in place for data access along with this access being restricted to DevOps Teams only.
Yes, data in transit is protected by TLS 1.2/1.3, certificate pinning, VPN, firewalls (WAF), IP whitelists.
Users access is restricted via RBAC and MFA. For all our tools we have SSO in place.
Yes, all access is logged with user agents along with IPs. Actions performed are logged with the Employee ID of the customer. Logs are retained for a defined period of 1 month for transient data and 12 months for retained actions.
Our synthetic alerts are setup for immediate detection of unauthorized actions or anomalies.
Yes, data can be exported in standard formats or via API, deleted securely from all locations, and all backups removed within 30 days in line with GDPR/compliance best practices.
Yes, we have a data protection policy
Our organization has assessed the obligation to appoint a Data Protection Officer (DPO) in accordance with applicable privacy regulations and has appointed a qualified DPO to oversee compliance. The DPO is formally designated internally and serves as the point of contact for data protection authorities and customers. Where legally required, the DPO’s appointment has been notified to the competent Supervisory Authority.
Employees processing personal data are regularly trained and sensitized on secure data handling, confidentiality, and privacy best practices.
We maintain an inventory (records of processing activities) of categories of personal information collected along with its usage, sources and specific purposes for collection (including GDPR)
The record is reviewed annually
Shipsy requires all subprocessors to meet equivalent data-protection guarantees via contractual flow-downs, pre-engagement due diligence, ongoing risk assessments, audit rights and enforceable deletion/return obligations as set out in our Vendor Management Policy
There is a periodic review of risks by management
Yes, 24/7 incident monitoring via likes of AWS GuardDuty/Security Hub and SIEM, with alerts to a security team and escalation matrix.
Yes, logs are centrally stored via ELK, encrypted at rest, made immutable, and access is strictly controlled and audited.
Yes, every action is tied to an individual (no shared accounts), all API/privileged accesses are logged to user/entity, and session and audit trails enable complete forensics and compliance.
Yes, real-time AWS GuardDuty, ML-based anomaly detection, alerting, network and behavioral analysis, and a 24/7 monitoring systems with predefined alerts help detection and escalation.
Yes, log management is covered in regular internal/external audits for SOC 2/ISO certifications, with findings addressed, verified by third parties, and audit summaries available for review.
Yes. We maintain a documented cyber incident management process covering detection, containment, investigation, remediation, and communication. Roles and escalation paths are clearly defined. The process is reviewed and updated regularly, and we conduct simulations at least annually (with ad-hoc tabletop drills for specific scenarios) to ensure preparedness.
Yes. In the event of a security incident requiring forensic investigation, our security and engineering teams perform the initial analysis (log review, system tracing, and evidence collection). For deep forensic expertise, we have the ability to engage trusted third-party specialists to conduct detailed investigations. This ensures that incidents are handled thoroughly and in accordance with industry best practices.
No major breaches occurred; minor events were handled through the incident plan, RCA, and regular improvements, with transparency and documentation available for review.
Yes we have a Vendor Management Policy which has provisions of Risks and Contractual Liabilities on Information Security.
Yes, all strategic subcontractors (AWS, GCP, Azure, CloudFlare, payment partners) are certified to SOC 2/ISO/PCI DSS/CREST standards and undergo regular security review.
Due diligence involves security questionnaires, certifications, reference checks, stability assessment, DPAs, regular audits, monitoring, and performance reviews.
Yes, all contracts enforce equivalent security, data protection, compliance, audit, certification and incident response requirements for all subcontractors.
Yes, main subprocessors: AWS/GCP/Azure for infra, MongoDB Atlas (DB), CloudFlare (CDN/DDoS), SendGrid/Twilio (communication), and accredited payment gateways. All subprocessors are under data processing agreements.
Yes, all suppliers undergo certification, compliance, legal, financial, and background vetting with ongoing monitoring as required by risk.
Yes, compliance is strictly maintained via Standard Contractual Clauses, adequacy, DPAs, regular audits, residency options, location transparency, and customer consent when needed.
Yes, some supplier contracts require notification within 24 hours but not all. We also use very limited Suppliers.
No significant third-party incidents; proactive monitoring, regular assessment, rapid response, incident coordination, and lessons learned practices prevent and mitigate issues.
SOC 2 Type 2 and ISO 27001 certifications are maintained.
Our solution leverages a Multi-AZ setup, providing built-in redundancy and high availability. This design supports our disaster recovery strategy by ensuring critical systems and data remain operational during infrastructure failures, minimizing downtime and maintaining business continuity.
All of our application running in Multi-AZ which offers business continuity even if the entire data center goes down.
Our BCP addresses critical threats including building inaccessibility or destruction, IT infrastructure failure, cyber-attacks, pandemics, and key provider failures. It ensures continuity of operations and rapid recovery to minimize business disruption.
Our BCP ensures resilience against physical, technical, and operational threats. Critical systems and data are backed up and replicated to a DR site in AWS Stockholm, supporting rapid failover. Teleworking infrastructure allows continuity during building inaccessibility or pandemics, and redundant key providers mitigate service disruptions. Regular backups, tested restore procedures, and security controls ensure minimal downtime and sustained operations under all major threat scenarios.
We assign a dedicated Account Manager to each client, serving as the primary contact for technical or operational issues and ensuring timely resolution and coordinated support.
Our platform includes comprehensive disaster recovery capabilities with enterprise-grade support services. The built-in disaster recovery features include active-active setup with read replicas across multiple availability zones, automated failover mechanisms, redundant backups in geographically separate locations, and regular backup testing protocols. For recovery support, we provide a 3-tier support structure with named contacts at each level - Level 1 Help Desk for initial response, and Level 2/3 direct access to Support Manager and VP Growth for escalations. Additional services include regular disaster recovery testing to ensure systems are ready when needed, zero data loss architecture with real-time replication and journaling, and multi-tier redundancy across application, database, and infrastructure layers. Associated costs for these services would depend on the specific deployment model chosen and can be discussed in detail based on specific deployment requirements.
Yes. Our documented Incident Management Plan includes a clear escalation process, designated key contacts, and defined reporting timescales to ensure timely response and resolution of incidents, minimizing business impact.
If an incident negatively impacts the continuity of service provided to a client, we inform the client promptly via email, phone, or designated communication channels. Notification is provided as soon as the incident is identified and assessed, with regular updates on remediation progress until resolution. This ensures transparency and enables clients to take any necessary interim actions.
Our governance framework assigns clear responsibilities across security, compliance, operations, and service delivery, with dedicated teams and an Account Manager overseeing each client.
Our operations and systems undergo regular internal and external audits, including ISO 27001 and SOC 2 to ensure security, compliance, and operational integrity.
Yes. All systems and services involved in GDPR-related data processing are designed to be highly resilient and are fully included within our Business Continuity Management System (BCMS). This ensures that personal data remains protected, accessible, and recoverable in the event of disruptions, while maintaining compliance with GDPR requirements.
Clients can reduce their maximum downtime by leveraging Multi-AZ deployments, real-time data replication, and dedicated support services. These features enhance system resilience, improve failover capabilities, and accelerate recovery in the event of disruptions.
Clients can reduce potential data loss by leveraging real-time data replication, frequent automated backups, and Multi-AZ deployments. These measures ensure that critical data remains protected and recoverable in the event of system failures or disruptions. Optional configurations can also be implemented to further minimize recovery point objectives (RPO) based on specific operational requirements.
We maintain a formal Data Governance Policy covering the framework, defined roles and responsibilities, and data quality procedures to ensure secure, accurate, and compliant data management.
We have regular data quality controls in place, including automated validation, periodic audits, and monitoring, to ensure accuracy, consistency, and compliance.
Our controls cover all key data quality dimensions: accuracy, completeness, consistency, timeliness, uniqueness, and validity.
We apply thresholds and automated checks to monitor data quality. Results are reviewed regularly, with corrective actions initiated when thresholds are breached.
Data quality issues are centrally tracked through established incident and defect management processes, with remediation assigned to data owners.
We generate internal reports and dashboards on data quality metrics and share relevant insights with stakeholders as needed.
If a data quality issue impacts client deliverables, clients are notified promptly through our incident communication process, along with remediation plans.
A formal change management process is in place. Clients are notified of technical or structural changes in advance through release notes, communications, or direct updates.