Security, Privacy & Architecture Specification
Official Enterprise Overview of Infrastructure Controls, Cryptographic Safeguards, Tenant Isolation & Compliance Standards
Security Philosophy & Overview
Panvaya provides unified tracking and intelligence for ocean containers, sailing schedules, and multimodal cargo movements. Because beneficial cargo owners (BCOs), freight forwarders, and logistics operators depend on our platform for operational decisions, information security and system availability are primary design criteria.
We enforce defense-in-depth principles across our hosting environment, application layer, and data pipelines. Customer shipment references, Bills of Lading, and commercial cargo details are protected by modern cryptographic standards, strict role-based access, and isolated multi-tenant data boundaries.
AWS Cloud Infrastructure
All production application components and databases are hosted on Amazon Web Services (AWS) within certified cloud regions. AWS facilities provide certified physical, environmental, and electrical safeguards, including 24/7 security personnel, biometric controls, redundant power, and environmental monitoring.
Production workloads run inside hardened, minimal containerized runtimes operating under least-privilege service roles. Application compute resources are kept logically isolated from underlying hardware and other cloud tenants.
Network Architecture & Edge Defense
Panvaya employs a layered network perimeter to filter malicious traffic before it reaches internal services:
Public internet traffic is routed through Cloudflare’s global network, providing automated denial-of-service (DDoS) mitigation, Web Application Firewall (WAF) filtering, and rate limiting.
Internal services and databases communicate through isolated Virtual Private Cloud (VPC) subnets. Databases and backend microservices are not assigned public internet addresses.
Encryption Standards (At Rest & In Transit)
All customer cargo data, account credentials, and communication channels are protected using strong cryptography:
All external HTTPS connections to the web application, user portal, and developer REST APIs are strictly enforced with TLS 1.3 and TLS 1.2 encryption. Unencrypted HTTP traffic is redirected.
Managed relational databases, document storage, and automated database snapshot backups are encrypted at rest using industry-standard AES-256 managed via AWS Key Management Service (KMS).
Qualys SSL Labs Benchmark: Grade A+
Live VerifiedStrict TLS 1.3 / 1.2 cipher suites, full forward secrecy, and 1-year HTTP Strict Transport Security (max-age=31536000).
Access Control & API Security
Authentication and authorization mechanisms follow the principle of least privilege:
Passwords are never stored in plaintext. Credentials use salted, adaptive one-way cryptographic hashing before storage.
Developer API keys are displayed once upon generation. Panvaya persists only an irreversible SHA-256 hash, preventing plaintext exposure.
Granular tenant permissions ensure users access only their assigned organization’s shipments and resources.
Data Storage & Production Isolation
Panvaya maintains strict operational segregation between production and lower environments:
Carrier Integration & Proxy Isolation
Panvaya aggregates milestones across global ocean shipping lines and airlines. To ensure operational stability:
Data Ownership & Privacy Guarantees
Your cargo tracking records, container identifiers, and commercial volumes remain your property:
High Availability & Business Continuity
Panvaya is built to provide reliable 24/7 visibility:
- Service Level Target: 99.9% availability target across core developer REST APIs.
- Rolling Deployments: Cloud container deployments execute rolling updates, verifying application health before routing traffic to updated service instances.
- Automated Backups: Daily automated encrypted database snapshots with retention policies and point-in-time recovery.
Compliance & Industry Standards Alignment
Panvaya benchmarks security, privacy, and architectural controls against established international frameworks:
Aligned with the Cloud Security Alliance (CSA) Consensus Assessments Initiative Questionnaire (CAIQ) standards for cloud security.
Independently benchmarked with Grade A+ rating for strict TLS 1.3/1.2 cipher suites, forward secrecy, and 1-year HSTS enforcement.
Hardened client perimeter enforcing anti-clickjacking (SAMEORIGIN), nosniff MIME protection, and strict referrer policies.
Cryptographically signed DNS records (ECDSA P-256) with verified DS trust anchor preventing DNS spoofing and cache poisoning.
Complies with European General Data Protection Regulation and California privacy statutes regarding data minimization and individual rights.
Emits normalized tracking events aligned with open Digital Container Shipping Association (DCSA) industry specifications.
Methodology aligned with Smart Freight Centre GLEC Framework v3.0 and ISO 14083 for Scope 3 emissions reporting and ESG audits.
Strict BIC container check-digit validation and United Nations UN/LOCODE coordinate normalization across all carrier feeds.
Standard DPA incorporating EU Standard Contractual Clauses (SCCs) ready for enterprise review. View DPA →
Security Inquiries & Responsible Disclosure
We welcome security questionnaires, vendor assessments, and responsible disclosure inquiries. For enterprise customers conducting vendor risk management or procurement diligence, detailed application security assessment reports, automated vulnerability scan summaries, and completed CSA STAR questionnaires are available upon request:
Panvaya InfoSec & Compliance Desk
Vendor Security Reviews, Questionnaires & Security Incident Reporting
Email: [email protected]