★ Independent Third-Party Verification

Security Audits & Compliance Certification

Audit Period: 2025–2026 Annual Assessment
•
Standard: SOC 2 Type II • ISO/IEC 27001
•
Status: ✓ Current & Certified
🛡
SOC 2 Type II Certified
✓ Audited Security Controls
⚗
ISO/IEC 27001 Standard
✓ Information Security System
🔐
256-Bit SSL/TLS Pipeline
✓ Encrypted Telemetry

SOC 2 Type II Attestation & Trust Principles

ShippingStatus Global Logistics Network, LLC undergoes annual independent Service Organization Control (SOC 2) Type II examinations conducted by accredited third-party CPA auditing firms. The comprehensive evaluation assesses our operational and technical controls against the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria:

  • Security: Perimeter network firewalls, strict role-based access control (RBAC), and multi-factor authentication across all logistics endpoints.
  • Availability: Redundant server infrastructure operating across distributed cloud regions ensuring 99.9% uptime for public tracking queries and internal dispatch feeds.
  • Confidentiality: Automated masking of recipient residential addresses and strict data classification policies preventing unauthorized disclosures.

Physical Sortation Hub & Gate Security

Digital security is matched by rigorous physical security measures across our six national sortation gateways (`EWR-01`, `ORD-02`, `ATL-03`, `DFW-04`, `LAX-05`, `PDX-06`):

  • Biometric Facility Access: High-security sorting zones, staging docks, and cross-docking terminals require dual-factor biometric credentials.
  • 24/7 Monitored CCTV Surveillance: Ultra-high-definition video coverage with AI-assisted optical monitoring covers all conveyor lines, sortation trays, and dispatch bays.
  • Tamper-Evident Security Seals: All high-value parcels undergo quality inspection where serialized tamper-evident security tape is affixed and photographed before dispatch.

Application Penetration Testing & Vulnerability Management

Our web tracking infrastructure, database storage layers, and API endpoints are evaluated through semi-annual black-box and gray-box penetration tests by certified CREST/OSCP security engineers:

  • Continuous Vulnerability Scanning: Automated daily dependency checks and static application security testing (SAST).
  • Defensive Rate Limiting: Standard 180 requests/minute rate-limiting shield preventing automated enumeration, dictionary attacks, and scrapers.
  • DDoS Mitigation: High-capacity traffic scrubbing networks protecting live tracking availability during high-volume transshipment peak periods.

Responsible Vulnerability Disclosure Program

ShippingStatus values the contributions of the global security research community. If you discover a potential security vulnerability within our platform, we invite you to report it to our Security Operations Center under our Safe Harbor Guidelines:

Security Operations Desk: [email protected]
Emergency Response SLA: Initial acknowledgment within 24 hours.