Security and data processing

Updated 2026-08-28

Where and how it runs

  • Every product runs on Microsoft Azure in United States (Microsoft Azure, Central US region): the web app, the tracking API and its worker as container apps, and a managed Azure Database for PostgreSQL with encryption at rest and automated backups.
  • All traffic is TLS-encrypted, between you and the site and between our services and providers.
  • The public site is delivered through a caching proxy operated by Ploy; the origin is reachable only over TLS.

Authentication and access control

  • Passwords are stored as salted scrypt hashes; sessions are cookie-based and expire.
  • API keys are stored as SHA-256 hashes, so a database copy yields nothing usable; each webhook endpoint has its own signing secret.
  • Shipments belong to an organization; teammates see only their organization’s board. Share links are read-only and scoped to the shipments chosen.
  • Supplier contact details are shown one company at a time to signed-in users and rate-limited, so they cannot be harvested in bulk.
  • Administrative access is limited to named superusers.

Payments

Payments are handled entirely by Stripe, a PCI DSS Level 1 provider. Card details are entered on Stripe’s pages and never pass through or rest on our systems.

Subprocessors

ProviderPurposeDataLocation
Microsoft AzureHosting, database, container registry and logs for every productAll service dataUnited States (Central US)
Ploy (runploy.com)Content delivery and caching proxy in front of www.matilogistics.comRequest metadata (IP address, user agent, URL) for every page view; cached page contentUnited States
AnthropicLanguage model behind the AI sourcing agent (see Methodology → AI sourcing agent)The sourcing request you type and the page it was typed on; no account detailsUnited States
StripePayments and subscriptions for Track and TraceBilling name, email, payment details (never stored by us)United States
ResendTransactional email (sign-up, password reset, notifications, inquiry receipts)Email address, name, message contentUnited States
Google AnalyticsAggregate usage analytics on the websitePseudonymous usage events, truncated IP address, device and browser dataUnited States
FindTEUTracking data aggregator used for one carrier (OOCL) in Track and TraceThe container number being tracked; nothing about youEuropean Union
IPRoyalProxy network through which some carrier tracking pages are fetchedThe request to the carrier, i.e. the tracking reference; nothing about youGlobal network

We will notify account holders by email before adding a subprocessor that handles personal data.

Incidents and vulnerabilities

  • If we confirm a security incident affecting your data, we will notify you without undue delay and within 72 hours of confirming it, with what happened, what was affected and what we are doing.
  • To report a vulnerability, email moyi@matilogistics.com. We will acknowledge within two business days and will not pursue good-faith researchers who avoid accessing others’ data and give us reasonable time to fix.

Certifications

We do not currently hold a SOC 2 or ISO 27001 certification. Our hosting provider does (Azure’s compliance offerings cover the infrastructure layer). We answer security questionnaires on request.

Data processing agreement

Where you need a DPA — for example under the GDPR or UK GDPR — email moyi@matilogistics.com and we will provide one, incorporating standard contractual clauses for transfers to the United States. Retention periods, your rights and the data each product handles are set out in the privacy policy.