Security & Data Handling
Reporting issues and protecting your data
How to responsibly disclose a vulnerability, and how we handle and protect the data you trust us with.
Vulnerability disclosure
If you believe you have found a security vulnerability, please report it to us so we can address it. We appreciate responsible disclosure and ask that you give us a reasonable opportunity to remediate before any public disclosure.
Please include steps to reproduce, affected components, and any supporting detail. Do not access or modify data that is not yours, and avoid actions that could degrade the service for others.
Data-handling policy
We handle your import documents and business data with controls appropriate to sensitive trade information.
- Encryption in transit (TLS) protects data moving between you and the platform.
- Role-based access controls limit who can view or act on your data.
- Per-tenant isolation keeps each organization’s documents and data separated.
- Document retention and deletion: you can request deletion of documents or account data, subject to applicable customs recordkeeping obligations.
- Sub-processors: we use vetted infrastructure and hosting providers; a current list is available on request. [TODO: publish maintained sub-processor list.]
Incident response
We maintain a process for responding to security events. At a high level, it follows these steps:
- 1Detect and triage: reported and monitored events are assessed for severity and scope.
- 2Contain and remediate: we work to limit impact and address the root cause.
- 3Notify: affected customers are notified where appropriate and as required by applicable law.
- 4Review: we conduct a post-incident review to strengthen controls.
Compliance readiness
We are working toward recognized security frameworks. These are goals in progress, not current certifications. We do not claim to hold any certification we have not earned.
Need our security documentation?
Contact us to request our current security overview, sub-processor list, or data-processing details.