Status: Active Production • Contact: security@cargooptix.com
Unlike legacy cloud logistics software that forces clients to transmit proprietary bill-of-lading and SKU manifests to remote servers, Cargo Optix executes its bin-packing and load-planning solvers locally in the browser using client-side C++ WebAssembly and WebGL. Your freight manifests, cargo dimensions, and bill of materials never touch our servers.
Cargo Optix enforces PostgreSQL Row-Level Security (RLS) on every table within Supabase. Even in multi-tenant environments, database queries are cryptographically constrained by authenticated JSON Web Tokens (JWT). Unauthorized cross-tenant reads or writes are programmatically blocked by database engine policies.
All subscription payments and pay-as-you-go run packs are processed directly via Stripe Elements. Cargo Optix operates under PCI-DSS SAQ-A compliance — payment card numbers, CVVs, and expiry dates are never transmitted through or stored on our infrastructure.
We welcome security researchers and customers to review our posture and report potential vulnerabilities responsibly. Our canonical security policy and disclosure channels are published at /.well-known/security.txt.
Security reports and vulnerability inquiries: security@cargooptix.com