Security, Privacy & Compliance
This page describes security practices, infrastructure and providers used to process shipping data. Contact our team for supporting documents needed for your review.
Compliance Status
We document every certification honestly: what we hold today, what's in progress, and what's not applicable.
PCI-DSS
Card fields use Stripe Elements. PCI compliance remains a shared responsibility; using Stripe does not automatically certify our platform.
PIPEDA
Canadian privacy law, fully applicable.
GDPR
GDPR-compatible practices (data export, right to erasure, DPA available).
SOC 2 Type II
Not certified. No SOC 2 report for our platform is currently published.
Annual Penetration Test
No independent penetration test report is currently published. Contact us for the status of any engagement.
ISO 27001
Evaluated based on enterprise customer demand.
Security Practices
Encryption in Transit
Public pages use HTTPS and publish an HSTS header to request encrypted connections from supporting browsers.
Encryption at Rest
Supabase documents AES-256 disk encryption for its infrastructure. This is a provider control, not native encryption of every Postgres field. Review specific requirements with our team.
Authentication & Access
Authentication uses Supabase Auth. Role checks and RLS policies protect access. Ask for scope and exception details for your assessment.
Multi-Factor Authentication
TOTP MFA available for all admin accounts. Customer-facing rollout in progress.
Rate Limiting
50+ API routes protected by Upstash Redis-backed rate limiting. Per-IP + per-user limits, standards-compliant Retry-After headers.
Monitoring & Alerts
Errors tracked via Sentry. Application logs in Vercel Observability. Alerts configured for error spikes and payment failures.
Audit Trails
Structured logs record instrumented administrative operations. Confirm their coverage and retention against your organization’s requirements.
Payment Idempotency
Payment flows use idempotency and duplicate controls. Their presence is not a guarantee that a payment error cannot occur.
BOLA Protection
Private-resource access uses ownership or role checks appropriate to the workflow. These controls form part of the defence against unauthorized access.
Input Validation
Input validation and field allowlists restrict changes accepted by the relevant workflows. Specific controls depend on the route.
Signed Webhooks
Easyship, SendGrid, and Stripe webhooks verified via HMAC signature with constant-time comparison (timingSafeEqual).
Bidirectional EDI 214
Standards-compliant X12 EDI 214 generation + parsing for enterprise partners. Native support for carrier shipment status feeds.
Infrastructure & Data Residency
Database
Supabase Postgres hosted in AWS ca-central-1 in Canada. Backup and restoration arrangements should be confirmed as part of your security review.
Compute
Next.js application hosted on Vercel. The verified deployment uses functions in the US iad1 region and a global CDN.
Storage
Supabase Storage (S3-backed). Label PDFs, invoices, brand assets. RLS-gated access.
Availability
Availability depends on the application and its providers. This page publishes neither historical uptime measurements nor a contractual service-level commitment; contact us to discuss your requirements.
Sub-Processors
Every third-party entity that processes customer data. Updated at least 30 days before any new sub-processor is added. To be notified of changes by email, contact privacy@mescolis.ca.
Provider reports and certifications apply to their own services and scope. They do not certify our platform.
| Vendor | Purpose | Data | Region | Documentation |
|---|---|---|---|---|
| Supabase | Database, authentication, file storage | User profiles, shipments, invoices, label PDFs | AWS · ca-central-1 (Canada) | View provider documentation |
| Vercel | Hosting, serverless functions, CDN | Code, data processed by functions and request logs | Functions: iad1 (USA) · Global CDN | View provider documentation |
| Stripe | Card payments, wallets, payment authorizations | Card data (never touched by us: handled by Stripe Elements) | Global | View provider documentation |
| PayPal | Alternative payments | PayPal order IDs, amounts | Global | View provider documentation |
| NOWPayments | Cryptocurrency payments | Wallet addresses, transaction IDs | EU | View provider documentation |
| SendGrid | Transactional emails (confirmations, invoices, tracking) | Email addresses, outbound email content | US | View provider documentation |
| Postmark | Inbound email reception (support tickets) | Received support emails | US | View provider documentation |
| Anthropic | Claude API for AI features (advisor, HS classification, vision) | AI prompts and responses; retention depends on provider terms and the features used | US | View provider documentation |
| Upstash | Rate limiting (Redis) | IP addresses, user IDs (short TTL) | AWS us-east-1 | View provider documentation |
| Sentry | Error tracking & observability | Stack traces (PII scrubbed before send) | US / EU | View provider documentation |
| Easyship | Carrier aggregator (rates, labels, tracking) | Shipment details, addresses, customs declarations | Singapore HQ | View provider documentation |
Data Handling
Data We Collect
Profile information (name, email, phone, address), shipment details (origin, destination, contents, customs declarations), payment data (via Stripe, never stored on our side), admin activity logs.
Retention
Active data retained for the lifetime of the account. After account deletion: profile and shipments removed within 30 days, invoices retained 7 years for Canadian tax compliance (CRA).
Right to Erasure
You can request account deletion at any time from Settings or by emailing privacy@mescolis.ca. We respond within 30 days per PIPEDA and GDPR.
Data Portability
Full data export available in CSV/JSON from your dashboard at Settings → Data. Includes profile, shipments, invoices, and tracking logs.
No Sale, No Ad Sharing
Your data is never sold, never shared for advertising. Period. No third-party marketing or analytics integration receives personal data.
Incident Response
In the event of a data breach or significant security incident, we commit to:
- Notify affected customers by email within 72 hours of incident confirmation
- Notify the relevant authorities (Office of the Privacy Commissioner of Canada) per PIPEDA
- Publish a detailed post-mortem on this page within 14 days of resolution
- Provide a dedicated support channel for affected customers
Incident history: This page is not a comprehensive incident register. Ask our team for the information needed for your security review.
Responsible Vulnerability Disclosure
We welcome reports from security researchers. If you discover a vulnerability, contact security@mescolis.ca with:
- A detailed description of the vulnerability
- Reproduction steps
- Potential impact
- Your contact for follow-up
We commit to acknowledging receipt within 2 business days, actively investigating, and coordinating public disclosure with you. We commit to not pursuing legal action against researchers acting in good faith.
Data Processing Agreement (DPA)
For customers subject to GDPR, PIPEDA, or contractual compliance requirements, we provide a standard DPA on request. Email privacy@mescolis.ca with your company name and the context of the request.
This page is updated regularly. Last updated: