How we protect customer data across our global logistics operations. Live posture below is drawn from the same authoritative controls we audit against — and we never present unknown status as passing.
Controls monitored
39%
Operating
9
Under attention
2
Unknown
12
Last tested 2026-07-21 · 23 controls in scope · unknown is shown as unknown, never as passing.
SOC 2 Type II
Security, Availability, Confidentiality
Valid through 2027-03-31
ISO/IEC 27001:2022
Certified ISMS
Valid through 2027-11-03
NIST CSF 2.0
Self-assessment in progress
Valid through 2026-10-01
Request gated documents
Restricted reports are released only after an NDA and approval — the document is never served before the policy is satisfied.
| Provider | Service | Region | Data |
|---|---|---|---|
| CloudFreight Inc. | TMS / freight orchestration | US | Operational, Customer PII |
| Nimbus Cloud Services | IaaS hosting | Global | Infrastructure |
| SentinelSOC | Managed detection & response | US | Security telemetry |
| PayrollPro EU | Payroll processing | EU | Employee PII, Financial |
| RoboPick Systems | Warehouse automation / OT | US | Operational |
In regional cloud environments (US, EU) with encryption at rest and in transit. Data residency is enforced per contract.
Yes. SSO via SAML/OIDC and enforced MFA for all workforce access to production systems.
Every subprocessor is risk-tiered, assessed before onboarding, and continuously monitored. See the subprocessor list on this page.
Per contractual timelines; our detection and response controls are continuously tested.