Security & Compliance

How we protect your data and support your compliance requirements.

Our commitment

At Cargo Pilot, we are committed to maintaining the privacy and security of your personal and business information. We do not sell or share your data with third parties. We take the protection of your data seriously and have implemented appropriate measures to keep it secure.

Security practices

Multi-Tenant Isolation

Each tenant operates in a fully isolated data environment. Business data is never shared or accessible across tenants. Master/sub-business hierarchies enforce strict write guards preventing unauthorized modifications to inherited data.

Self-Hosted Deployment

Enterprise customers can deploy Cargo Pilot in their own infrastructure for full data sovereignty. Self-hosted instances give organizations complete control over where their data resides and how it is accessed.

API Security

API access is restricted to Premium and Enterprise plans with authenticated access. No API rate limiting is applied, but all requests are authenticated and authorized against tenant-scoped permissions.

Audit Trails

Full inventory movement history for every stock change — purchases, sales, transfers, adjustments, assemblies, returns, and write-offs. Every movement records the running balance and links to the source document. Price change history and purchase order lifecycle tracking provide complete traceability.

Data Portability

You have full access to your data at all times via API or data export. No vendor lock-in — migrate between supported integrations without disruption to your business operations. Data backups can be provided on request.

Integration Security

All integrations with third-party platforms (eCommerce, accounting, CRM, workflow tools) use secure authentication methods. Webhook endpoints support verification. RabbitMQ connections are encrypted.

Compliance & governance

Tax Compliance

Multi-jurisdiction support for VAT, Sales Tax, and other regional tax models across all supported markets.

HS Code Management

Product classification for customs and import/export compliance, supporting international trade workflows.

Procurement Governance

Purchase order approval workflows, budget controls, and master-business enforcement of procurement rules across sub-businesses.

GDPR-Compliant Data Handling

Personal data is handled in accordance with GDPR principles. Users can download, update, and delete their data directly from their account.

Workflow Governance

Enforce business rules consistently through workflow orchestration. Version control and audit trails for all workflow changes.

Supplier Compliance

Track certifications, insurance, and contract renewals through automated workflows. Monitor supplier performance through delivery and quality metrics.

Architecture

Deployment Multi-tenant SaaS or self-hosted
Scalability Horizontally scalable architecture
Multi-Tenancy Master/sub-business hierarchy with data inheritance
Integration Webhooks, RabbitMQ, REST APIs

Data ownership

With Cargo Pilot you have access to your products, customers, reports, and workflow data from one single dashboard. You are not locked into any single platform. With Cargo Pilot you can migrate between supported integrations without your business operations being affected.

  • Full data export capabilities
  • API access to all your data
  • No vendor lock-in
  • GDPR-compliant data handling
  • Data portability between platforms

Report a vulnerability

If you discover a security vulnerability, please report it responsibly by contacting us at [email protected] or through our contact form.

Questions about security?

Get in touch to learn more about how we protect your data.