Skip to content

Security and privacy posture

Clear controls. No invented assurances.

This page describes the current Shipvanta product surface. It is not a certification, a data-processing agreement, or a substitute for your organization's own security review.

Workspace-scoped access

Shipvanta supports workspace owners, admins, and members. Workspace membership is used to scope product records and review activity.

Scoped API and webhook controls

The product includes API credential management and signed webhook delivery configuration. External receivers and any external-system integration remain your implementation responsibility.

Product data posture

Shipment-packet records and document metadata remain available in the workspace while it is active. Supported packet records can be accessed through the product API when credentials are configured; document-file downloads are not included in that API surface.

Availability and support

Shipvanta is delivered as a web application. We monitor and maintain the product, but this page does not make an uptime, recovery-time, or service-level agreement promise.

Retention and export

The product currently retains active-workspace packet records and related document metadata. There is no public marketing promise of an automatic deletion schedule, archival policy, full data export, or document-file export. Discuss contractual retention, access, and offboarding needs before rollout.

Compliance boundary

Shipvanta supports human review and configured deterministic checks. It does not make customs decisions, validate HTS codes against live authorities, submit filings, or certify regulatory compliance. Your users remain responsible for all customs and regulatory decisions.

Discuss your procurement requirements
    Security, Privacy, and Data Posture | Shipvanta