Third Party Index

Snapshot 58182

Document
Security page
URL
https://panvaya.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
144690 bytes
SHA-256 (raw)
8cf3b2f8f6900e59c4eb3fcd39723b4344f7fd6b069a4b9c47261d456cd32e45
SHA-256 (normalized text)
d71296d5563d7cfd582376ff0ccc936c92ca4642d555632589f2cb1d8ae565a2

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Panvaya Trust & SecurityCSA STAR Level 1 Registered →Enterprise Standards
Security, Privacy & Architecture
Our comprehensive overview of infrastructure controls, cryptographic safeguards, production isolation, and customer data ownership commitments.
Effective: 1 Sep 2026Enterprise OverviewMulti-Tenant Isolation
Security Architecture
Enterprise InfoSec Review
Need vendor security questionnaires (SIG / CAIQ), DPA execution, or dedicated enterprise compliance reviews?
CSA STAR Level 1 Registered →[email protected]Request Security Package →
PANVAYA LOGISTICS INTELLIGENCEEFFECTIVE: 1 SEP 2026
Security, Privacy & Architecture Specification
Official Enterprise Overview of Infrastructure Controls, Cryptographic Safeguards, Tenant Isolation & Compliance Standards
01
Security Philosophy & Overview
Panvaya provides unified tracking and intelligence for ocean containers, sailing schedules, and multimodal cargo movements. Because beneficial cargo owners (BCOs), freight forwarders, and logistics operators depend on our platform for operational decisions, information security and system availability are primary design criteria.
We enforce defense-in-depth principles across our hosting environment, application layer, and data pipelines. Customer shipment references, Bills of Lading, and commercial cargo details are protected by modern cryptographic standards, strict role-based access, and isolated multi-tenant data boundaries.
02
AWS Cloud Infrastructure
All production application components and databases are hosted on Amazon Web Services (AWS) within certified cloud regions. AWS facilities provide certified physical, environmental, and electrical safeguards, including 24/7 security personnel, biometric controls, redundant power, and environmental monitoring.
Production workloads run inside hardened, minimal containerized runtimes operating under least-privilege service roles. Application compute resources are kept logically isolated from underlying hardware and other cloud tenants.
03
Network Architecture & Edge Defense
Panvaya employs a layered network perimeter to filter malicious traffic before it reaches internal services:
Edge Filtering & DDoS Mitigation
Public internet traffic is routed through Cloudflare’s global network, providing automated denial-of-service (DDoS) mitigation, Web Application Firewall (WAF) filtering, and rate limiting.
Isolated VPC Segments
Internal services and databases communicate through isolated Virtual Private Cloud (VPC) subnets. Databases and backend microservices are not assigned public internet addresses.
04
Encryption Standards (At Rest & In Transit)
All customer cargo data, account credentials, and communication channels are protected using strong cryptography:
Encryption in Transit (TLS 1.3 & TLS 1.2)
All external HTTPS connections to the web application, user portal, and developer REST APIs are strictly enforced with TLS 1.3 and TLS 1.2 encryption. Unencrypted HTTP traffic is redirected.
Encryption at Rest (AES-256)
Managed relational databases, document storage, and automated database snapshot backups are encrypted at rest using industry-standard AES-256 managed via AWS Key Management Service (KMS).
A+
Qualys SSL Labs Benchmark: Grade A+
Live Verified
Strict TLS 1.3 / 1.2 cipher suites, full forward secrecy, and 1-year HTTP Strict Transport Security (max-age=31536000).
View SSL Report
05
Access Control & API Security
Authentication and authorization mechanisms follow the principle of least privilege:
Credential Hashing
Passwords are never stored in plaintext. Credentials use salted, adaptive one-way cryptographic hashing before storage.
Hashed API Keys
Developer API keys are displayed once upon generation. Panvaya persists only an irreversible SHA-256 hash, preventing plaintext exposure.
Role-Based Access (RBAC)
Granular tenant permissions ensure users access only their assigned organization’s shipments and resources.
06
Data Storage & Production Isolation
Panvaya maintains strict operational segregation between production and lower environments:
Private Database Subnets:Relational database clusters reside exclusively within private cloud network zones with no external public routing. All interactions are mediated through authenticated application services.
Zero Direct Database Access Policy:Our operational policy strictly prohibits direct, ad-hoc, or unmonitored human access to production databases. System metrics, structured error reporting, and sanitised staging environments are used for maintenance and testing.
07
Carrier Integration & Proxy Isolation
Panvaya aggregates milestones across global ocean shipping lines and airlines. To ensure operational stability:
Isolated Outbound Proxy Infrastructure:Outbound tracking queries and schedule crawlers route through dedicated proxy gateways. Internal production network IP addresses are never exposed to external carrier networks.
Automated Secret & Token Masking:Application logging automatically masks authorization tokens, API keys, and sensitive fields before writing logs.
08
Data Ownership & Privacy Guarantees
Your cargo tracking records, container identifiers, and commercial volumes remain your property:
Multi-Tenant Logical Segregation:Customer data is partitioned logically with organization-level scoping. Tenants cannot view, query, or enumerate records belonging to other organizations.
Strict Non-Sale Pledge:We do not sell, rent, broker, or license customer cargo data, reference numbers, or trade volumes to third parties or advertisers.
No Foundation AI Training on Customer Records:Customer cargo manifests, container records, and custom notes are strictly excluded from training public or commercial AI models.
09
High Availability & Business Continuity
Panvaya is built to provide reliable 24/7 visibility:
Service Level Target: 99.9% availability target across core developer REST APIs.
Rolling Deployments: Cloud container deployments execute rolling updates, verifying application health before routing traffic to updated service instances.
Automated Backups: Daily automated encrypted database snapshots with retention policies and point-in-time recovery.
10
Compliance & Industry Standards Alignment
Panvaya benchmarks security, privacy, and architectural controls against established international frameworks:
Cloud Security Alliance (CSA) STAR Level 1
Official Registry Listing
CAIQ-Lite v4.1 • Continuous Cloud Security Self-Assessment
View Registry Entry
Panvaya is officially registered on the public CSA Security, Trust, Assurance, and Risk (STAR) Registry. Our Consensus Assessments Initiative Questionnaire (CAIQ-Lite v4.1) documents our self-assessment of cloud governance, isolation, key management and data protection controls. STAR Level 1 is a self-assessment, not an independent security certification.
Qualys SSL Labs: Grade A+
Independently benchmarked with Grade A+ rating for strict TLS 1.3/1.2 cipher suites, forward secrecy, and 1-year HSTS enforcement.
SecurityHeaders.com: Grade A
Hardened client perimeter enforcing anti-clickjacking (SAMEORIGIN), nosniff MIME protection, and strict referrer policies.
DNSSEC Protected Zone
Cryptographically signed DNS records (ECDSA P-256) with verified DS trust anchor preventing DNS spoofing and cache poisoning.
GDPR & CCPA Aligned
Complies with European General Data Protection Regulation and California privacy statutes regarding data minimization and individual rights.
DCSA Milestone Normalization
Emits normalized tracking events aligned with open Digital Container Shipping Association (DCSA) industry specifications.
GLEC Framework & ISO 14083:2023
Indicative calculations use a GLEC-aligned methodology and maintained emissions factors. Results are planning estimates, not independently verified ISO 14083 emissions reports or ESG audit evidence.
ISO 6346 & UN/LOCODE Standards
Strict BIC container check-digit validation and United Nations UN/LOCODE coordinate normalization across all carrier feeds.
Data Processing Agreement (DPA)
Standard DPA incorporating EU Standard Contractual Clauses (SCCs) ready for enterprise review. View DPA →
11
Security Inquiries & Responsible Disclosure
We welcome security questionnaires, vendor assessments, and responsible disclosure inquiries. For enterprise customers conducting vendor risk management or procurement diligence, detailed application security assessment reports, automated vulnerability scan summaries, and completed CSA STAR questionnaires are available upon request:
Panvaya InfoSec & Compliance Desk
Vendor Security Reviews, Questionnaires & Security Incident Reporting
Email: [email protected]
Contact Security Desk