Skip to content
iCarriage AI

Security

What we do, and what we haven't done yet.

Freight files contain commercial terms, party identities and customs data. Here is our actual posture — including the parts still in progress.

In place today

  • Tenant isolation. Every record carries a tenant identifier and is isolated at the database row level. Retrieval for the AI copilot is scoped to the requesting tenant.
  • Immutable audit trail. Approvals, rejections, classification overrides and document actions are appended with actor identity and timestamp. Entries are not editable through the application.
  • Authenticated access. Signed, expiring session tokens with role-based route access. Tokens are verified on every API request, and separately at the edge before protected pages are served.
  • Encryption. TLS in transit. Data at rest is encrypted by the managed database and object storage services we run on.
  • Least-privilege documents. Documents are served through short-lived pre-signed URLs rather than public links.
  • Screening controls. Denied-party screening is enforced server-side; a high-confidence match blocks approval rather than raising a dismissible warning.
  • Retention policy. Per-shipment retention schedules covering FMC, CBP and COGSA windows, with archival and purge eligibility tracked.

In progress

We would rather tell you this than let you assume it. The following are on the Phase 1 pre-launch checklist and are not complete:

  • Third-party penetration test and a formal SOC 2 Type II programme. We hold no certification today and do not claim one.
  • Single sign-on and SCIM provisioning for enterprise tenants.
  • Customer-managed encryption keys.
  • A published uptime SLA. Availability commitments are currently agreed contract by contract.

Reporting a vulnerability

Email security@icarriageai.com with enough detail to reproduce. We will acknowledge within two business days and keep you updated until it is resolved. Please give us a reasonable window before public disclosure, and don't run automated scans against production or access data that isn't yours — we will not pursue good-faith research that follows those two rules.

Sub-processors and data location

Customer data is hosted in the United States. A current list of sub-processors is provided as part of our data processing agreement — see the data processing page or ask us directly.