TRUST CENTER

Built for the standards European financial institutions work to.

This page sets out how Shipit24 handles security, data protection and compliance. It is updated as we add certifications and capabilities — we describe exactly where each item stands, and never claim what isn't in place.

Certifications & attestations

Each item shows its current status. Reports are available under NDA where noted.

SOC 2 Type II

Trust services criteria. Type II examination targeted for Q4 2026.

pending In progress

ISO/IEC 27001

Information security management. On the roadmap for 2027.

event_upcoming Planned · 2027

PCI DSS scope

Shipit24 does not store cardholder data; payment flows are handled by the partner's own processor.

info Out of scope

GDPR Article 28 DPA

Article 28 Data Processing Agreement available on request.

check_circle Available

Data protection

Data residency

Customer and parcel data is stored in EU regions with EU-based hosting providers.

Encryption

AES-256 at rest, TLS 1.3 in transit.

Data retention

Retention aligned to the purpose of processing; customers can export historical data at any time.

Right to erasure

Data-subject requests handled per GDPR, including erasure and rectification.

Sub-processors

Third parties that may process customer data on our behalf. Categories shown; the full current list with named providers is available on request and in the DPA.

CategoryPurposeLocation
Cloud hostingApplication & data hostingEU
Transactional emailAccount & shipment notificationsEU
Error monitoringReliability & diagnosticsEU
CarriersParcel delivery & trackingEU + UK

Operational security

  • bug_reportPenetration testing on a regular cadence, with attestations shared under NDA.
  • policyVulnerability disclosure — a security.txt at /.well-known/security.txt and a monitored security@shipit24.eu inbox.
  • codeSecure SDLC — code review, dependency scanning and secure coding practices.
  • keyAccess controls — SSO, MFA and least-privilege access to production systems.

Incident response

Severity classification

Incidents are triaged and classified by severity to drive response.

Notification SLA

Affected customers notified within 24 hours of a confirmed incident.

Post-mortems

Confirmed incidents receive a documented post-incident review.

Regulatory positioning

Legal entity. Shipit24 OÜ, registered in Estonia.

Regulator status. Shipit24 operates as a technology service provider, not a regulated financial institution.

DORA. We support DORA-regulated customers through inclusion in third-party risk registers, ICT incident reporting cooperation, and documented exit plans.

GDPR & UK GDPR. We act as a data processor under a GDPR Article 28 DPA for both EU and UK data protection regimes.

Business continuity

Availability. We publish realistic uptime targets and operate carrier-level failover so shipments continue even when a single carrier's API is unavailable.

Resilience. Disaster-recovery and failover architecture across EU regions.

Exit assistance. Customers can leave at any time. We provide a full data export and transition support — no exit fees.

Documentation & contact

The DPA, security overview, and pen-test attestation are available to customers and prospects — some under NDA. Security questions go straight to a real person.