Security at Shipvale
This page is maintained by Shipvale to answer common security and privacy questions from merchants evaluating our fulfillment and tracking platform.
Encryption in transit & at rest
All traffic is served over TLS 1.2+. Data stored in our primary database is encrypted at rest using AES-256.
Least-privilege access
Production access is restricted to authorized engineers, gated by SSO and multi-factor authentication. Row-level security enforces per-merchant isolation.
Resilient infrastructure
The platform runs on globally distributed edge infrastructure with automatic failover, daily encrypted backups, and 30-day point-in-time recovery.
Responsible logging
We collect the minimum diagnostic data needed to operate the service. Sensitive fields are redacted before logs leave the request path.
Shared responsibility
Shipvale secures the platform, the infrastructure, and the data we hold on your behalf. Merchants are responsible for protecting their own account credentials, managing team access, and ensuring the accuracy of the recipient information they submit for shipping.
Report a vulnerability
If you believe you've found a security issue, please email security@shipvale.com. We acknowledge reports within 2 business days and will keep you updated as we investigate.
This page is maintained by Shipvale and is not an independent certification.