← Return to Cargo Optix
SECURITY & INFRASTRUCTURE

Security Standards & Architecture

Status: Active Production • Contact: security@cargooptix.com

1. Zero-Exposure Manifest Processing

Unlike legacy cloud logistics software that forces clients to transmit proprietary bill-of-lading and SKU manifests to remote servers, Cargo Optix executes its bin-packing and load-planning solvers locally in the browser using client-side C++ WebAssembly and WebGL. Your freight manifests, cargo dimensions, and bill of materials never touch our servers.

2. Data Encryption in Transit & at Rest

3. Row-Level Security (RLS) & Multi-Tenant Isolation

Cargo Optix enforces PostgreSQL Row-Level Security (RLS) on every table within Supabase. Even in multi-tenant environments, database queries are cryptographically constrained by authenticated JSON Web Tokens (JWT). Unauthorized cross-tenant reads or writes are programmatically blocked by database engine policies.

4. Payment Security & PCI-DSS

All subscription payments and pay-as-you-go run packs are processed directly via Stripe Elements. Cargo Optix operates under PCI-DSS SAQ-A compliance — payment card numbers, CVVs, and expiry dates are never transmitted through or stored on our infrastructure.

5. Vulnerability Disclosure & RFC 9116

We welcome security researchers and customers to review our posture and report potential vulnerabilities responsibly. Our canonical security policy and disclosure channels are published at /.well-known/security.txt.

Security reports and vulnerability inquiries: security@cargooptix.com