Security at QueChains

Enterprise-grade trust
for global logistics data

QueChains is built for regulated supply chain operations, with encryption, tenant isolation, audit trails, and compliance workflows designed in from day one.

TLS 1.3 RBAC Audit logs MFA

Four pillars of protection

Technical and organizational controls work together so your shipments, customs data, and partner information stay confidential and intact.

Encryption & data protection

Your logistics data is encrypted in transit and at rest, with tenant-scoped access controls.

  • TLS 1.3 for all HTTPS and WebSocket traffic
  • AES-256 encryption for sensitive fields at rest
  • Tenant-isolated document and file storage

Identity & access

Every API call is authenticated, authorized, and scoped to your organization.

  • Short-lived access tokens with automatic expiry
  • Server-managed refresh tokens and session revocation
  • Role-based access control on every route
  • Multi-factor authentication (TOTP) available

Infrastructure & resilience

Production workloads run on hardened cloud infrastructure with monitoring and rate limits.

  • Cloud-hosted services with network segmentation
  • Per-user and per-organization API rate limiting
  • Schema validation on all inbound API requests
  • 99.5% platform uptime target

Audit & monitoring

Immutable logs and proactive monitoring help you meet compliance and investigate incidents.

  • Immutable audit trail for every write action
  • Structured logging and centralised error reporting

Security practices

Defense in depth
Layered controls across network, application, and data tiers β€” not a single perimeter.
Tenant isolation
Organization ID enforced on queries, caches, and storage so customer data never commingles.
Secure SDLC
Code review, dependency scanning, and staged rollouts before production releases.
Penetration testing
Regular third-party assessments and remediation tracking for identified findings.
Incident response
Documented playbooks with 72-hour breach notification aligned to GDPR requirements.
Secrets management
API keys and credentials stored in secure vaults β€” never in source code or client bundles.
  • Employee security training and least-privilege access to production
  • Background checks for roles with access to customer data
  • Vendor risk reviews for all third-party sub-processors
  • Business continuity and disaster recovery planning
  • Data retention aligned with trade compliance (7–10 year shipment records)

Built for regulated industries

We align with international privacy, trade compliance, and payment security standards, with certifications in progress where noted.

πŸ‡ͺπŸ‡Ί
GDPR Aligned
EU data protection practices
πŸ‡ΊπŸ‡Έ
CCPA Ready
California privacy requirements
πŸ’³
PCI DSS
Payments via Stripe
🚒
C-TPAT Support
Enterprise tier programs

Report a vulnerability

If you discover a security issue, please report it responsibly to our security team. We acknowledge valid reports within 48 hours and work with researchers under coordinated disclosure.

[email protected]

Security documentation

Enterprise customers can request our security overview, sub-processor list, and data processing agreement. See also our Privacy Policy for data handling details.

In the event of a data breach affecting personal data, QueChains will notify affected users and relevant authorities within 72 hours as required by GDPR and applicable law.

Need a security review?

Our team supports enterprise questionnaires, architecture reviews, and pilot security assessments for qualified deployments.