Your carrier credentials
are not our product.
We exist to move packages, not to monetize your data. Here's exactly how we handle your shipping data, carrier accounts, and customer information.
Data storage & encryption
Encryption at rest
All data stored in our infrastructure uses AES-256 encryption. Carrier credentials are stored separately from shipment data in an isolated vault with additional access controls.
Encryption in transit
All API traffic uses TLS 1.3. We enforce HTTPS on every endpoint. HTTP requests are permanently redirected to HTTPS — no exceptions.
Database isolation
Customer data is logically isolated per account. A query that touches your shipments cannot touch another customer's data by design, not just by convention.
Backup & recovery
Daily encrypted backups with point-in-time recovery. Backups are stored in geographically separate regions. Recovery objective: 4 hours or less.
Carrier credentials
Your FedEx, UPS, and DHL account numbers are the most sensitive data in a shipping platform. Here's exactly how we handle them:
- Carrier credentials are stored in an isolated secrets vault, separate from all other data
- Credentials are never logged, never included in error messages, and never returned in API responses
- Access to the credential vault requires separate authentication from the main application
- You can revoke carrier connections at any time from your settings — deletion is immediate and permanent
- We do not use your carrier accounts for anything beyond processing your shipments
Customer data (your buyers)
When your orders sync to LogixVast, they include your buyers' shipping addresses. Here's our policy on that data:
- Buyer shipping addresses are used solely to generate labels and submit tracking
- We do not sell, share, or analyze buyer data for any commercial purpose
- Buyer data is deleted 90 days after a shipment is delivered, unless you request retention for returns
- GDPR data deletion requests are processed within 30 days
Access controls & authentication
Two-factor authentication
TOTP-based 2FA available on all accounts. Enterprise plans can enforce 2FA as a requirement for all team members.
SSO / SAML (Enterprise)
Enterprise plans support SSO via Okta, Azure AD, Google Workspace, and custom SAML 2.0 identity providers.
Role-based access
Assign team members as Viewers, Shippers, or Admins. Viewers see orders but can't generate labels. Admins manage billing and integrations.
API key rotation
API keys can be rotated at any time without downtime. Webhooks support secret rotation on the fly. Old keys expire after 24 hours of rotation.
Incident response
If we ever detect a security issue that affects customer data:
- Affected customers are notified within 72 hours of discovery
- Notification includes what was affected, what we've done, and what you should do
- Post-incident report published to our status page within 14 days
- Security issues can be reported to security@logixvast.com
Questions or concerns?
Enterprise customers can request our full security documentation, penetration test reports, and SOC 2 audit status. Contact security@logixvast.com.