Security & Compliance

Your freight data,
handled properly.

Cargopulse holds your shipments, your customers and your money flows. We treat that data the way a forwarder treats a high-value consignment — encrypted, tracked, and never out of your control.

Encrypted TLS in transit. Off-site encrypted backups. Active
GDPR Compliant by default. DPA available. Active
Tenant isolation Separate database per customer. No shared tables. Active
EU-hosted OVHcloud, France. Backups stay in the EU. Active
How it works

Defence in depth.

Security isn't one feature — it's how the whole system is built. Here's what protects your data at each layer.

01 · Encryption

Encrypted everywhere

  • TLS 1.3 in transit
  • HTTPS everywhere — no plaintext endpoints
  • Encrypted off-site backups
  • Access-controlled document storage
02 · Access

Least privilege

  • Role-based permissions
  • SSO — Google & Microsoft sign-in
  • IP network fencing available per user
  • Tenant isolation by design
03 · Operations

Watched & backed up

  • Continuous monitoring
  • Daily encrypted backups
  • Error tracking & alerting, 24/7
  • Hardened, minimal-surface servers
04 · Governance

Provable & portable

  • Entity-level audit trail on core records
  • Data export any time
  • Right-to-erasure honoured on request
  • Signed DPA & sub-processor list

Your data stays
in Europe.

Shipments, documents and invoices are stored and processed on our infrastructure at OVHcloud in France, with encrypted backups kept in the EU. Transactional email and AI inference run through vetted providers under GDPR safeguards — the full list is on our sub-processor page.

FranceOVHcloud · primary
EUencrypted backups
Pulsie AI

AI that stays
on your side of the wall.

Your data does not train anyone's model.

Pulsie reads your jobs and documents to do its work — drafting, reconciling, answering. That's it. Your shipment data is never used to train foundation models, never shared across customers, and only processed by AI providers under enterprise terms that exclude training. Pulsie only acts on records the asking user already has permission to see.

No training on customer data — ever
Strict per-tenant data isolation
Permission-scoped: Pulsie sees only what the user can
Inference under enterprise API terms — no training, no retention beyond processing
Documentation

Everything your
security team needs.

Request our security package, or read the public documents below. Deeper architecture detail available under NDA.

Sync your supply chain. Feel the pulse.

Bring your
security questions.

We'll walk your IT and compliance teams through architecture, hosting and data handling — and hand over the full package under NDA.