Customs declarations, suppliers and costs are commercially sensitive data. Here's how we handle them — in detail, because "we take security seriously" means nothing.
Isolation is enforced by the database, not just by the application: every row belongs to one company and without that context the answer is zero rows. The app has no privilege to get around it (PostgreSQL Row-Level Security in FORCE mode, application role with no bypass).
An automated suite attempts to read and write another company's data on every single change — including a guard that fails if someone accidentally removes the protections. If it doesn't pass, the code doesn't ship.
Infrastructure and AI models on servers in the EU (Azure). Your documents stay inside the European perimeter even during automated reading.
Every customs declaration or quote is read twice, with two independent methods (layout analysis and a vision model), with a reading reliability score. If the reading fails, the document drops into manual entry: never an invented figure. Totals that don't add up are flagged.
Payments are handled by Stripe (hosted checkout and portal): card numbers and bank details never pass through — and are never stored on — our systems.
The back office sees counts and metadata (how many declarations, how many logins), never the contents: no declaration numbers, supplier names or financial values. It's a database constraint, verified — not a trust-based policy.
Creations, changes, deletions and exports are recorded with user, date and IP address (audit log). Passwords are stored only in irreversible form (bcrypt hash); mandatory email verification, a cap on repeated attempts (rate limiting), full security headers.
Optional two-step verification with an authenticator app (TOTP MFA), passwordless login with an emailed code, rules on password length and variety. Sessions can be revoked, lockout after failed attempts. VAT numbers are checked against the EU register (VIES) when company tax data is saved.
Every key belongs to one company, has defined permissions and can be revoked instantly; it is stored encrypted. Included calls are counted on the server and every response contains only that company's data, with the same isolation as the rest of the platform.
Technical questions or a DPA request? Get in touch. On request we share the detail of how the isolation is built.