SOC 2
Review the applicable report, assessment period and scope through the security review process.
Enterprise-grade security
AI Operators work with your operational data and connected systems. Shipflow combines layered safeguards with configurable SOPs, permissions and human approval checkpoints.
Review the applicable report, assessment period and scope through the security review process.
Confirm the certificate’s scope and validity against your procurement requirements.
Review our published Privacy Policy and request the enterprise Data Processing Addendum.
Your data and AI
AI Operators may analyze the communications, documents and operational information you connect to perform requested tasks. For Customer Data, Shipflow generally acts as a processor or service provider under the customer agreement and documented instructions.
As stated in our Privacy Policy, we do not use Customer Data to train publicly available models. Model-provider terms, processing arrangements and data retention are reviewed separately for your deployment.
Read our AI processing policyPermissions and access
Deployment planning identifies the mailboxes, records, interfaces and actions needed for an agreed workflow. Reading a request, preparing a response and sending an external commitment are different permissions and operating decisions.
We scope connections with your system owners, including approved identities, available access controls and any write actions. Agree how access is granted, reviewed and revoked in each connected system. The available controls depend on the application and connection method; an integration does not imply unrestricted access to your environment.
Explore system integrationsHuman control
AI Operators follow the configured SOPs and escalation rules for each workflow. Your team defines which routine tasks can proceed and which decisions require judgment. Missing information, conflicting documents or actions outside agreed rules are routed to the responsible person with the context needed to act.
Approval checkpoints are configured around the operation, rather than applying one blanket rule to every task. Examples to agree with your team include:
Data protection
Shipflow’s security approach includes infrastructure and encryption safeguards, access control and device management. Use the Trust Center and security review to confirm the current implementation, including encryption standards and the separation of customer information.
Customer Data retention is primarily determined by customer agreements and configuration. At the end of the Services, deletion or return follows the customer agreement and applicable law; some information may be retained for legal obligations or dispute resolution.
Our Privacy Policy states that information may be processed in the United States and other jurisdictions. Confirm your hosting, location and transfer requirements during review rather than assuming a particular data-residency option.
Read retention and privacy detailsCompliance and review
Start with the Trust Center to review Shipflow’s current security posture. Confirm the applicable reports, certificate scope and validity, and any information requiring a separate access request. Assurance documentation should be evaluated against the services and workflow you plan to use.
A Data Processing Addendum is available for enterprise customers upon request or may be incorporated into the customer agreement. Bring your security questionnaire and requirements for model providers, subprocessors, access, retention and incident communication so the relevant arrangements can be reviewed before rollout.
Open the Trust CenterCommon questions
Our Privacy Policy states that Customer Data is not used to train publicly available models. Ask for the processing terms relevant to the model providers and services in your deployment.
Yes. Approval checkpoints and escalation rules are configured around your SOPs and agreed workflow. Your team defines the decisions that require an authorized reviewer.
Start with the Trust Center for current security information. Contact Shipflow to discuss your review requirements or request an enterprise Data Processing Addendum.
Plan a controlled rollout
Share your security requirements alongside the operation you want to automate. We’ll discuss the data, systems and approval boundaries in scope.
Discuss security requirements