Protected staff access
Approved staff require a password, confirmed TOTP device, active staff status and authorized group membership.
Security
The implemented foundation reduces public disclosure and restricts operational access without exposing infrastructure detail.
Overview
Approved staff require a password, confirmed TOTP device, active staff status and authorized group membership.
Shipment operations use managed group permissions with no direct-user permission grants or superuser bypass.
Exact lookup, high-entropy identifiers and a strict public allowlist prevent raw model exposure.
Public lookup uses bounded rate limiting, CSRF protection and private no-store responses.
Tracking events are append-only and reviewed authentication and shipment actions retain audit records.
Raw tracking searches, client IP addresses, cookies and session values are not persisted by public tracking.
Common questions
Yes. Approved staff access requires password and a confirmed time-based one-time-password device.
No. Result responses are private, no-store and noindex.