Snapshot 58182
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Panvaya Trust & SecurityCSA STAR Level 1 Registered →Enterprise Standards Security, Privacy & Architecture Our comprehensive overview of infrastructure controls, cryptographic safeguards, production isolation, and customer data ownership commitments. Effective: 1 Sep 2026Enterprise OverviewMulti-Tenant Isolation Security Architecture Enterprise InfoSec Review Need vendor security questionnaires (SIG / CAIQ), DPA execution, or dedicated enterprise compliance reviews? CSA STAR Level 1 Registered →[email protected]Request Security Package → PANVAYA LOGISTICS INTELLIGENCEEFFECTIVE: 1 SEP 2026 Security, Privacy & Architecture Specification Official Enterprise Overview of Infrastructure Controls, Cryptographic Safeguards, Tenant Isolation & Compliance Standards 01 Security Philosophy & Overview Panvaya provides unified tracking and intelligence for ocean containers, sailing schedules, and multimodal cargo movements. Because beneficial cargo owners (BCOs), freight forwarders, and logistics operators depend on our platform for operational decisions, information security and system availability are primary design criteria. We enforce defense-in-depth principles across our hosting environment, application layer, and data pipelines. Customer shipment references, Bills of Lading, and commercial cargo details are protected by modern cryptographic standards, strict role-based access, and isolated multi-tenant data boundaries. 02 AWS Cloud Infrastructure All production application components and databases are hosted on Amazon Web Services (AWS) within certified cloud regions. AWS facilities provide certified physical, environmental, and electrical safeguards, including 24/7 security personnel, biometric controls, redundant power, and environmental monitoring. Production workloads run inside hardened, minimal containerized runtimes operating under least-privilege service roles. Application compute resources are kept logically isolated from underlying hardware and other cloud tenants. 03 Network Architecture & Edge Defense Panvaya employs a layered network perimeter to filter malicious traffic before it reaches internal services: Edge Filtering & DDoS Mitigation Public internet traffic is routed through Cloudflare’s global network, providing automated denial-of-service (DDoS) mitigation, Web Application Firewall (WAF) filtering, and rate limiting. Isolated VPC Segments Internal services and databases communicate through isolated Virtual Private Cloud (VPC) subnets. Databases and backend microservices are not assigned public internet addresses. 04 Encryption Standards (At Rest & In Transit) All customer cargo data, account credentials, and communication channels are protected using strong cryptography: Encryption in Transit (TLS 1.3 & TLS 1.2) All external HTTPS connections to the web application, user portal, and developer REST APIs are strictly enforced with TLS 1.3 and TLS 1.2 encryption. Unencrypted HTTP traffic is redirected. Encryption at Rest (AES-256) Managed relational databases, document storage, and automated database snapshot backups are encrypted at rest using industry-standard AES-256 managed via AWS Key Management Service (KMS). A+ Qualys SSL Labs Benchmark: Grade A+ Live Verified Strict TLS 1.3 / 1.2 cipher suites, full forward secrecy, and 1-year HTTP Strict Transport Security (max-age=31536000). View SSL Report 05 Access Control & API Security Authentication and authorization mechanisms follow the principle of least privilege: Credential Hashing Passwords are never stored in plaintext. Credentials use salted, adaptive one-way cryptographic hashing before storage. Hashed API Keys Developer API keys are displayed once upon generation. Panvaya persists only an irreversible SHA-256 hash, preventing plaintext exposure. Role-Based Access (RBAC) Granular tenant permissions ensure users access only their assigned organization’s shipments and resources. 06 Data Storage & Production Isolation Panvaya maintains strict operational segregation between production and lower environments: Private Database Subnets:Relational database clusters reside exclusively within private cloud network zones with no external public routing. All interactions are mediated through authenticated application services. Zero Direct Database Access Policy:Our operational policy strictly prohibits direct, ad-hoc, or unmonitored human access to production databases. System metrics, structured error reporting, and sanitised staging environments are used for maintenance and testing. 07 Carrier Integration & Proxy Isolation Panvaya aggregates milestones across global ocean shipping lines and airlines. To ensure operational stability: Isolated Outbound Proxy Infrastructure:Outbound tracking queries and schedule crawlers route through dedicated proxy gateways. Internal production network IP addresses are never exposed to external carrier networks. Automated Secret & Token Masking:Application logging automatically masks authorization tokens, API keys, and sensitive fields before writing logs. 08 Data Ownership & Privacy Guarantees Your cargo tracking records, container identifiers, and commercial volumes remain your property: Multi-Tenant Logical Segregation:Customer data is partitioned logically with organization-level scoping. Tenants cannot view, query, or enumerate records belonging to other organizations. Strict Non-Sale Pledge:We do not sell, rent, broker, or license customer cargo data, reference numbers, or trade volumes to third parties or advertisers. No Foundation AI Training on Customer Records:Customer cargo manifests, container records, and custom notes are strictly excluded from training public or commercial AI models. 09 High Availability & Business Continuity Panvaya is built to provide reliable 24/7 visibility: Service Level Target: 99.9% availability target across core developer REST APIs. Rolling Deployments: Cloud container deployments execute rolling updates, verifying application health before routing traffic to updated service instances. Automated Backups: Daily automated encrypted database snapshots with retention policies and point-in-time recovery. 10 Compliance & Industry Standards Alignment Panvaya benchmarks security, privacy, and architectural controls against established international frameworks: Cloud Security Alliance (CSA) STAR Level 1 Official Registry Listing CAIQ-Lite v4.1 • Continuous Cloud Security Self-Assessment View Registry Entry Panvaya is officially registered on the public CSA Security, Trust, Assurance, and Risk (STAR) Registry. Our Consensus Assessments Initiative Questionnaire (CAIQ-Lite v4.1) documents our self-assessment of cloud governance, isolation, key management and data protection controls. STAR Level 1 is a self-assessment, not an independent security certification. Qualys SSL Labs: Grade A+ Independently benchmarked with Grade A+ rating for strict TLS 1.3/1.2 cipher suites, forward secrecy, and 1-year HSTS enforcement. SecurityHeaders.com: Grade A Hardened client perimeter enforcing anti-clickjacking (SAMEORIGIN), nosniff MIME protection, and strict referrer policies. DNSSEC Protected Zone Cryptographically signed DNS records (ECDSA P-256) with verified DS trust anchor preventing DNS spoofing and cache poisoning. GDPR & CCPA Aligned Complies with European General Data Protection Regulation and California privacy statutes regarding data minimization and individual rights. DCSA Milestone Normalization Emits normalized tracking events aligned with open Digital Container Shipping Association (DCSA) industry specifications. GLEC Framework & ISO 14083:2023 Indicative calculations use a GLEC-aligned methodology and maintained emissions factors. Results are planning estimates, not independently verified ISO 14083 emissions reports or ESG audit evidence. ISO 6346 & UN/LOCODE Standards Strict BIC container check-digit validation and United Nations UN/LOCODE coordinate normalization across all carrier feeds. Data Processing Agreement (DPA) Standard DPA incorporating EU Standard Contractual Clauses (SCCs) ready for enterprise review. View DPA → 11 Security Inquiries & Responsible Disclosure We welcome security questionnaires, vendor assessments, and responsible disclosure inquiries. For enterprise customers conducting vendor risk management or procurement diligence, detailed application security assessment reports, automated vulnerability scan summaries, and completed CSA STAR questionnaires are available upon request: Panvaya InfoSec & Compliance Desk Vendor Security Reviews, Questionnaires & Security Incident Reporting Email: [email protected] Contact Security Desk