Built for the standards European financial institutions work to.
This page sets out how Shipit24 handles security, data protection and compliance. It is updated as we add certifications and capabilities — we describe exactly where each item stands, and never claim what isn't in place.
Certifications & attestations
Each item shows its current status. Reports are available under NDA where noted.
SOC 2 Type II
Trust services criteria. Type II examination targeted for Q4 2026.
ISO/IEC 27001
Information security management. On the roadmap for 2027.
PCI DSS scope
Shipit24 does not store cardholder data; payment flows are handled by the partner's own processor.
GDPR Article 28 DPA
Article 28 Data Processing Agreement available on request.
Data protection
Data residency
Customer and parcel data is stored in EU regions with EU-based hosting providers.
Encryption
AES-256 at rest, TLS 1.3 in transit.
Data retention
Retention aligned to the purpose of processing; customers can export historical data at any time.
Right to erasure
Data-subject requests handled per GDPR, including erasure and rectification.
Sub-processors
Third parties that may process customer data on our behalf. Categories shown; the full current list with named providers is available on request and in the DPA.
Operational security
- bug_reportPenetration testing on a regular cadence, with attestations shared under NDA.
- policyVulnerability disclosure — a
security.txtat/.well-known/security.txtand a monitored security@shipit24.eu inbox. - codeSecure SDLC — code review, dependency scanning and secure coding practices.
- keyAccess controls — SSO, MFA and least-privilege access to production systems.
Incident response
Severity classification
Incidents are triaged and classified by severity to drive response.
Notification SLA
Affected customers notified within 24 hours of a confirmed incident.
Post-mortems
Confirmed incidents receive a documented post-incident review.
Regulatory positioning
Legal entity. Shipit24 OÜ, registered in Estonia.
Regulator status. Shipit24 operates as a technology service provider, not a regulated financial institution.
DORA. We support DORA-regulated customers through inclusion in third-party risk registers, ICT incident reporting cooperation, and documented exit plans.
GDPR & UK GDPR. We act as a data processor under a GDPR Article 28 DPA for both EU and UK data protection regimes.
Business continuity
Availability. We publish realistic uptime targets and operate carrier-level failover so shipments continue even when a single carrier's API is unavailable.
Resilience. Disaster-recovery and failover architecture across EU regions.
Exit assistance. Customers can leave at any time. We provide a full data export and transition support — no exit fees.
Documentation & contact
The DPA, security overview, and pen-test attestation are available to customers and prospects — some under NDA. Security questions go straight to a real person.