Enterprise-grade security

Built for modern
logistics operations.

AI Operators work with your operational data and connected systems. Shipflow combines layered safeguards with configurable SOPs, permissions and human approval checkpoints.

Compliance and assurance

SOC 2

Review the applicable report, assessment period and scope through the security review process.

ISO 27001 certification

Confirm the certificate’s scope and validity against your procurement requirements.

GDPR-compliant data practices

Review our published Privacy Policy and request the enterprise Data Processing Addendum.

Your data and AI

Customer data, used for your workflows.

AI Operators may analyze the communications, documents and operational information you connect to perform requested tasks. For Customer Data, Shipflow generally acts as a processor or service provider under the customer agreement and documented instructions.

As stated in our Privacy Policy, we do not use Customer Data to train publicly available models. Model-provider terms, processing arrangements and data retention are reviewed separately for your deployment.

Read our AI processing policy

Permissions and access

Define what an AI Operator can do.

Deployment planning identifies the mailboxes, records, interfaces and actions needed for an agreed workflow. Reading a request, preparing a response and sending an external commitment are different permissions and operating decisions.

We scope connections with your system owners, including approved identities, available access controls and any write actions. Agree how access is granted, reviewed and revoked in each connected system. The available controls depend on the application and connection method; an integration does not imply unrestricted access to your environment.

Explore system integrations

Human control

Your SOPs. Your approval boundaries.

AI Operators follow the configured SOPs and escalation rules for each workflow. Your team defines which routine tasks can proceed and which decisions require judgment. Missing information, conflicting documents or actions outside agreed rules are routed to the responsible person with the context needed to act.

Approval checkpoints are configured around the operation, rather than applying one blanket rule to every task. Examples to agree with your team include:

  • BookingReview exceptions or carrier submissions where approval is required.
  • QuotationReview margin exceptions and customer commitments before release.
  • TenderingKeep final prices, carrier awards and material rate changes with authorized reviewers.
Explore controlled workflows

Data protection

Safeguards throughout the data lifecycle.

Shipflow’s security approach includes infrastructure and encryption safeguards, access control and device management. Use the Trust Center and security review to confirm the current implementation, including encryption standards and the separation of customer information.

Customer Data retention is primarily determined by customer agreements and configuration. At the end of the Services, deletion or return follows the customer agreement and applicable law; some information may be retained for legal obligations or dispute resolution.

Our Privacy Policy states that information may be processed in the United States and other jurisdictions. Confirm your hosting, location and transfer requirements during review rather than assuming a particular data-residency option.

Read retention and privacy details

Compliance and review

Bring your security team into the conversation.

Start with the Trust Center to review Shipflow’s current security posture. Confirm the applicable reports, certificate scope and validity, and any information requiring a separate access request. Assurance documentation should be evaluated against the services and workflow you plan to use.

A Data Processing Addendum is available for enterprise customers upon request or may be incorporated into the customer agreement. Bring your security questionnaire and requirements for model providers, subprocessors, access, retention and incident communication so the relevant arrangements can be reviewed before rollout.

Open the Trust Center

Common questions

Before your security review.

Does Shipflow use our data to train public AI models?

Our Privacy Policy states that Customer Data is not used to train publicly available models. Ask for the processing terms relevant to the model providers and services in your deployment.

Can we choose which actions need human approval?

Yes. Approval checkpoints and escalation rules are configured around your SOPs and agreed workflow. Your team defines the decisions that require an authorized reviewer.

Where can we review security documents or request a DPA?

Start with the Trust Center for current security information. Contact Shipflow to discuss your review requirements or request an enterprise Data Processing Addendum.

Plan a controlled rollout

Review the workflow.
Agree the safeguards.

Share your security requirements alongside the operation you want to automate. We’ll discuss the data, systems and approval boundaries in scope.

Discuss security requirements