Security and data processing
Updated 2026-08-28
Where and how it runs
- Every product runs on Microsoft Azure in United States (Microsoft Azure, Central US region): the web app, the tracking API and its worker as container apps, and a managed Azure Database for PostgreSQL with encryption at rest and automated backups.
- All traffic is TLS-encrypted, between you and the site and between our services and providers.
- The public site is delivered through a caching proxy operated by Ploy; the origin is reachable only over TLS.
Authentication and access control
- Passwords are stored as salted scrypt hashes; sessions are cookie-based and expire.
- API keys are stored as SHA-256 hashes, so a database copy yields nothing usable; each webhook endpoint has its own signing secret.
- Shipments belong to an organization; teammates see only their organization’s board. Share links are read-only and scoped to the shipments chosen.
- Supplier contact details are shown one company at a time to signed-in users and rate-limited, so they cannot be harvested in bulk.
- Administrative access is limited to named superusers.
Payments
Payments are handled entirely by Stripe, a PCI DSS Level 1 provider. Card details are entered on Stripe’s pages and never pass through or rest on our systems.
Subprocessors
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Microsoft Azure | Hosting, database, container registry and logs for every product | All service data | United States (Central US) |
| Ploy (runploy.com) | Content delivery and caching proxy in front of www.matilogistics.com | Request metadata (IP address, user agent, URL) for every page view; cached page content | United States |
| Anthropic | Language model behind the AI sourcing agent (see Methodology → AI sourcing agent) | The sourcing request you type and the page it was typed on; no account details | United States |
| Stripe | Payments and subscriptions for Track and Trace | Billing name, email, payment details (never stored by us) | United States |
| Resend | Transactional email (sign-up, password reset, notifications, inquiry receipts) | Email address, name, message content | United States |
| Google Analytics | Aggregate usage analytics on the website | Pseudonymous usage events, truncated IP address, device and browser data | United States |
| FindTEU | Tracking data aggregator used for one carrier (OOCL) in Track and Trace | The container number being tracked; nothing about you | European Union |
| IPRoyal | Proxy network through which some carrier tracking pages are fetched | The request to the carrier, i.e. the tracking reference; nothing about you | Global network |
We will notify account holders by email before adding a subprocessor that handles personal data.
Incidents and vulnerabilities
- If we confirm a security incident affecting your data, we will notify you without undue delay and within 72 hours of confirming it, with what happened, what was affected and what we are doing.
- To report a vulnerability, email moyi@matilogistics.com. We will acknowledge within two business days and will not pursue good-faith researchers who avoid accessing others’ data and give us reasonable time to fix.
Certifications
We do not currently hold a SOC 2 or ISO 27001 certification. Our hosting provider does (Azure’s compliance offerings cover the infrastructure layer). We answer security questionnaires on request.
Data processing agreement
Where you need a DPA — for example under the GDPR or UK GDPR — email moyi@matilogistics.com and we will provide one, incorporating standard contractual clauses for transfers to the United States. Retention periods, your rights and the data each product handles are set out in the privacy policy.