Security

Controls designed into staff and tracking workflows.

The implemented foundation reduces public disclosure and restricts operational access without exposing infrastructure detail.

Overview

What to expect

Protected staff access

Approved staff require a password, confirmed TOTP device, active staff status and authorized group membership.

Role permissions

Shipment operations use managed group permissions with no direct-user permission grants or superuser bypass.

Tracking privacy

Exact lookup, high-entropy identifiers and a strict public allowlist prevent raw model exposure.

Abuse controls

Public lookup uses bounded rate limiting, CSRF protection and private no-store responses.

Accountable history

Tracking events are append-only and reviewed authentication and shipment actions retain audit records.

Data minimisation

Raw tracking searches, client IP addresses, cookies and session values are not persisted by public tracking.

Common questions

Helpful detail

Does staff login use two factors?

Yes. Approved staff access requires password and a confirmed time-based one-time-password device.

Are public tracking results indexed?

No. Result responses are private, no-store and noindex.