Security

We sell compliance.
We practise it.

Customs declarations, suppliers and costs are commercially sensitive data. Here's how we handle them — in detail, because "we take security seriously" means nothing.

🔒 Each company sees only its own data

Isolation is enforced by the database, not just by the application: every row belongs to one company and without that context the answer is zero rows. The app has no privilege to get around it (PostgreSQL Row-Level Security in FORCE mode, application role with no bypass).

🧪 Tested on every code change

An automated suite attempts to read and write another company's data on every single change — including a guard that fails if someone accidentally removes the protections. If it doesn't pass, the code doesn't ship.

🇪🇺 Data and AI in Europe

Infrastructure and AI models on servers in the EU (Azure). Your documents stay inside the European perimeter even during automated reading.

📄 How we read your documents

Every customs declaration or quote is read twice, with two independent methods (layout analysis and a vision model), with a reading reliability score. If the reading fails, the document drops into manual entry: never an invented figure. Totals that don't add up are flagged.

💳 No card details with us

Payments are handled by Stripe (hosted checkout and portal): card numbers and bank details never pass through — and are never stored on — our systems.

👁 Even our own staff have limits

The back office sees counts and metadata (how many declarations, how many logins), never the contents: no declaration numbers, supplier names or financial values. It's a database constraint, verified — not a trust-based policy.

📜 Every change leaves a trace

Creations, changes, deletions and exports are recorded with user, date and IP address (audit log). Passwords are stored only in irreversible form (bcrypt hash); mandatory email verification, a cap on repeated attempts (rate limiting), full security headers.

🔑 Protected access

Optional two-step verification with an authenticator app (TOTP MFA), passwordless login with an emailed code, rules on password length and variety. Sessions can be revoked, lockout after failed attempts. VAT numbers are checked against the EU register (VIES) when company tax data is saved.

🔌 API keys with the same limits

Every key belongs to one company, has defined permissions and can be revoked instantly; it is stored encrypted. Included calls are counted on the server and every response contains only that company's data, with the same isolation as the rest of the platform.

Technical questions or a DPA request? Get in touch. On request we share the detail of how the isolation is built.