Panvaya Trust & SecurityEnterprise Standards

Security, Privacy & Architecture

Our comprehensive overview of infrastructure controls, cryptographic safeguards, production isolation, and customer data ownership commitments.

Effective: 1 Sep 2026Enterprise OverviewMulti-Tenant Isolation
01

Security Philosophy & Overview

Panvaya provides unified tracking and intelligence for ocean containers, sailing schedules, and multimodal cargo movements. Because beneficial cargo owners (BCOs), freight forwarders, and logistics operators depend on our platform for operational decisions, information security and system availability are primary design criteria.

We enforce defense-in-depth principles across our hosting environment, application layer, and data pipelines. Customer shipment references, Bills of Lading, and commercial cargo details are protected by modern cryptographic standards, strict role-based access, and isolated multi-tenant data boundaries.


02

AWS Cloud Infrastructure

All production application components and databases are hosted on Amazon Web Services (AWS) within certified cloud regions. AWS facilities provide certified physical, environmental, and electrical safeguards, including 24/7 security personnel, biometric controls, redundant power, and environmental monitoring.

Production workloads run inside hardened, minimal containerized runtimes operating under least-privilege service roles. Application compute resources are kept logically isolated from underlying hardware and other cloud tenants.


03

Network Architecture & Edge Defense

Panvaya employs a layered network perimeter to filter malicious traffic before it reaches internal services:

Edge Filtering & DDoS Mitigation

Public internet traffic is routed through Cloudflare’s global network, providing automated denial-of-service (DDoS) mitigation, Web Application Firewall (WAF) filtering, and rate limiting.

Isolated VPC Segments

Internal services and databases communicate through isolated Virtual Private Cloud (VPC) subnets. Databases and backend microservices are not assigned public internet addresses.


04

Encryption Standards (At Rest & In Transit)

All customer cargo data, account credentials, and communication channels are protected using strong cryptography:

Encryption in Transit (TLS 1.3 & TLS 1.2)

All external HTTPS connections to the web application, user portal, and developer REST APIs are strictly enforced with TLS 1.3 and TLS 1.2 encryption. Unencrypted HTTP traffic is redirected.

Encryption at Rest (AES-256)

Managed relational databases, document storage, and automated database snapshot backups are encrypted at rest using industry-standard AES-256 managed via AWS Key Management Service (KMS).


05

Access Control & API Security

Authentication and authorization mechanisms follow the principle of least privilege:

Credential Hashing

Passwords are never stored in plaintext. Credentials use salted, adaptive one-way cryptographic hashing before storage.

Hashed API Keys

Developer API keys are displayed once upon generation. Panvaya persists only an irreversible SHA-256 hash, preventing plaintext exposure.

Role-Based Access (RBAC)

Granular tenant permissions ensure users access only their assigned organization’s shipments and resources.


06

Data Storage & Production Isolation

Panvaya maintains strict operational segregation between production and lower environments:

Private Database Subnets:Relational database clusters reside exclusively within private cloud network zones with no external public routing. All interactions are mediated through authenticated application services.
Zero Direct Database Access Policy:Our operational policy strictly prohibits direct, ad-hoc, or unmonitored human access to production databases. System metrics, structured error reporting, and sanitised staging environments are used for maintenance and testing.

07

Carrier Integration & Proxy Isolation

Panvaya aggregates milestones across global ocean shipping lines and airlines. To ensure operational stability:

Isolated Outbound Proxy Infrastructure:Outbound tracking queries and schedule crawlers route through dedicated proxy gateways. Internal production network IP addresses are never exposed to external carrier networks.
Automated Secret & Token Masking:Application logging automatically masks authorization tokens, API keys, and sensitive fields before writing logs.

08

Data Ownership & Privacy Guarantees

Your cargo tracking records, container identifiers, and commercial volumes remain your property:

Multi-Tenant Logical Segregation:Customer data is partitioned logically with organization-level scoping. Tenants cannot view, query, or enumerate records belonging to other organizations.
Strict Non-Sale Pledge:We do not sell, rent, broker, or license customer cargo data, reference numbers, or trade volumes to third parties or advertisers.
No Foundation AI Training on Customer Records:Customer cargo manifests, container records, and custom notes are strictly excluded from training public or commercial AI models.

09

High Availability & Business Continuity

Panvaya is built to provide reliable 24/7 visibility:

  • Service Level Target: 99.9% availability target across core developer REST APIs.
  • Rolling Deployments: Cloud container deployments execute rolling updates, verifying application health before routing traffic to updated service instances.
  • Automated Backups: Daily automated encrypted database snapshots with retention policies and point-in-time recovery.

10

Compliance & Industry Standards Alignment

Panvaya benchmarks security, privacy, and architectural controls against established international frameworks:

CSA STAR Level 1 (Self-Assessment)

Aligned with the Cloud Security Alliance (CSA) Consensus Assessments Initiative Questionnaire (CAIQ) standards for cloud security.

Qualys SSL Labs: Grade A+

Independently benchmarked with Grade A+ rating for strict TLS 1.3/1.2 cipher suites, forward secrecy, and 1-year HSTS enforcement.

SecurityHeaders.com: Grade A

Hardened client perimeter enforcing anti-clickjacking (SAMEORIGIN), nosniff MIME protection, and strict referrer policies.

DNSSEC Protected Zone

Cryptographically signed DNS records (ECDSA P-256) with verified DS trust anchor preventing DNS spoofing and cache poisoning.

GDPR & CCPA Aligned

Complies with European General Data Protection Regulation and California privacy statutes regarding data minimization and individual rights.

DCSA Milestone Normalization

Emits normalized tracking events aligned with open Digital Container Shipping Association (DCSA) industry specifications.

GLEC Framework & ISO 14083:2023

Methodology aligned with Smart Freight Centre GLEC Framework v3.0 and ISO 14083 for Scope 3 emissions reporting and ESG audits.

ISO 6346 & UN/LOCODE Standards

Strict BIC container check-digit validation and United Nations UN/LOCODE coordinate normalization across all carrier feeds.

Data Processing Agreement (DPA)

Standard DPA incorporating EU Standard Contractual Clauses (SCCs) ready for enterprise review. View DPA →


11

Security Inquiries & Responsible Disclosure

We welcome security questionnaires, vendor assessments, and responsible disclosure inquiries. For enterprise customers conducting vendor risk management or procurement diligence, detailed application security assessment reports, automated vulnerability scan summaries, and completed CSA STAR questionnaires are available upon request:

Panvaya InfoSec & Compliance Desk

Vendor Security Reviews, Questionnaires & Security Incident Reporting

Email: [email protected]