Shiplab Information Security Overview
1. Introduction
At Shiplab, we take information security seriously. Protecting our customers’ shipping and invoice data is a core priority. We implement industry-leading security measures to safeguard confidentiality, integrity, and availability, ensuring that our systems and customer data remain secure.
2. Security Governance & Compliance
Shiplab follows a structured security program aligned with industry best practices. Our security framework is designed to protect data, maintain compliance, and mitigate risk across our infrastructure.
- We follow security principles that align with SOC 2, ISO 27001, and AWS Security Best Practices to ensure a secure and compliant environment.
- We continuously evaluate and improve our security posture through regular security assessments and risk management practices.
3. Cloud Infrastructure & Data Protection
Shiplab operates entirely on Amazon Web Services (AWS) and utilizes its built-in security controls to ensure high availability, scalability, and protection.
- Data in Transit: All data exchanged between Shiplab and customers is encrypted using Transport Layer Security (TLS 1.2+).
- Data at Rest: All customer data is encrypted using AES-256, an industry-standard encryption protocol.
- Access Controls: Role-based access control (RBAC) and Principle of Least Privilege (PoLP) ensure that only authorized users can access customer data.
- Data Segmentation: Customer data is logically separated within our environment to prevent unauthorized access.
4. Security Practices
- Continuous Monitoring: We monitor our infrastructure for unauthorized access, anomalies, and security threats.
- Security Audits & Reviews: We conduct regular security reviews to assess risks, validate access controls, and implement necessary security patches.
- Authentication Controls: We enforce Multi-Factor Authentication (MFA) and other security measures to protect access to our systems.
- Software Updates & Patch Management: Security updates and patches are applied as part of our ongoing risk management strategy.
- Network & System Security: Shiplab employs firewalls, intrusion detection, and automated security monitoring to protect against potential threats.
5. Data Security & Handling
Shiplab applies strict controls to protect customer data throughout its lifecycle.
- Data Classification & Protection: We use structured security measures to protect data from unauthorized access or exposure.
- Encryption: Sensitive data is encrypted both in transit (TLS 1.2+) and at rest (AES-256).
- Controlled Access: System access is restricted to authorized personnel based on business need.
- Data Retention & Disposal: Data is retained only as long as necessary for operational, legal, or regulatory purposes and is securely deleted when no longer required.
6. Secure Development Practices
Shiplab follows secure software development principles to protect our platform and customer data.
- Code Reviews: All code changes undergo peer reviews to ensure security and reliability before deployment.
- Vulnerability Management: We scan and address potential security vulnerabilities in our software development lifecycle.
7. Disaster Recovery & Business Continuity
Shiplab has a disaster recovery and business continuity plan in place to ensure service availability and resilience.
- High Availability: Our infrastructure is designed for redundancy and failover protection to minimize service disruptions.
- Data Backups: We maintain secure, encrypted backups to protect against data loss.
- Incident Response: In the event of a service disruption, Shiplab follows a structured recovery plan to restore operations as quickly as possible.
8. Personnel Security & Access Controls
Shiplab ensures that employees and contractors adhere to security policies to protect customer data.
- Security Awareness: All employees undergo security awareness training during onboarding and at regular intervals.
- Access Management: System access is role-based, follows the Principle of Least Privilege (PoLP), and is reviewed periodically.
- Offboarding Security: Access is promptly revoked when an employee or contractor leaves the company or changes roles that no longer require access.
9. Incident Response
- Incident Management Framework: Shiplab has a structured incident response plan to quickly detect, contain, and mitigate security risks.
- Security Breach Notification: In the event of a data breach, Shiplab will notify affected parties in accordance with applicable regulations.
10. Compliance & Legal
- Shiplab adheres to applicable legal and regulatory requirements related to data security and privacy.
- Our security policies and procedures are regularly updated to align with evolving compliance standards and industry best practices.
12. Contact
For security inquiries or concerns, please contact:
ipsec@shiplab.com

