Security & Trust
This overview describes current CargoFlow security practices and product controls. It is informational, not a certification, warranty, or service-level agreement.
1. Access and account controls
- Server-side authentication and authorization protect application data and API routes.
- Tenant and role controls are designed to separate organizations, internal users, and Customer Portal viewers.
- Privileged Administrator workflows use multi-factor authentication controls.
- Session cookies and sensitive API responses use restrictive security and cache controls.
- Security and audit events are recorded for selected account, access, and administrative actions.
2. Application and browser protections
CargoFlow uses HTTPS and restrictive browser-security headers, including Content Security Policy, HSTS, frame restrictions, MIME sniffing protections, referrer controls, and related response controls. CargoFlow also uses same-origin and request-validation controls on sensitive write operations.
3. Documents and uploaded files
- Document uploads are validated for file type, declared size, chunk integrity, and maximum-size controls.
- Completed documents receive a SHA-256 content hash that is checked when the file is retrieved.
- Executable or risky content types are restricted.
- When malware scanning is enabled and configured, uploaded document bytes may be scanned by the configured malware provider and unsafe or unresolved content can be blocked from customer-facing release workflows.
- Email-file previews are extracted for user review without requiring CargoFlow to execute active content from the message.
Malware screening is a defense-in-depth control, not a warranty that every document is safe. Customers should maintain endpoint security and avoid opening unexpected or suspicious attachments.
4. Connected-service credentials
Google Gmail refresh tokens used by the optional Carrier Inbox are encrypted before storage. CargoFlow requests Gmail read-only access and does not use that connection to send, delete, edit, label, or archive Gmail messages. Disconnecting Gmail removes the stored refresh token and CargoFlow attempts to revoke it with Google.
CargoFlow's current Outlook draft workflow does not store Microsoft 365 OAuth credentials or access a Microsoft mailbox. The user reviews a draft before the browser opens Outlook Web.
5. Data minimization and retention
CargoFlow maintains retention controls for certain short-lived integration and public-request records, including the Gmail Carrier Inbox review queue and anti-abuse data. The Privacy Policy and Data & Account Removal page describe current retention and request handling in more detail.
6. Incident response
CargoFlow investigates suspected security incidents, works to contain and remediate confirmed issues, preserves information reasonably needed for investigation, and evaluates customer or individual notification obligations under applicable contracts and law. Where applicable law requires a specific or shorter notification timing, CargoFlow will follow that requirement.
Customers should promptly report suspected account compromise, unauthorized access, or a security concern to support@cargoflowdg.com.
7. Shared responsibility
Security also depends on Customer practices. Customers are responsible for protecting user devices and credentials, assigning only needed permissions, removing departed users promptly, verifying recipients before sharing documents or portal access, and deciding what information is appropriate to place in CargoFlow.
8. Independent certifications and security reviews
Unless CargoFlow expressly states otherwise in a current signed document, CargoFlow does not claim a particular external certification such as SOC 2 or ISO 27001. Customers may request reasonable security information for procurement or risk review, subject to confidentiality and protection of sensitive security details.
9. Service providers
See Subprocessors & Connected Services for current infrastructure, email, document-security, Gmail, and carrier-integration disclosures.