Security & Compliance

Enterprise-Grade SecurityYou Can Trust

Your customs data is sensitive business information. We've implemented comprehensive security measures and maintain strict compliance with international data protection standards.

Comprehensive Security Measures

Multiple layers of protection for your data and operations

End-to-End Encryption

All data is encrypted in transit and at rest using AES-256 encryption standards

GDPR Compliant

Full compliance with European data protection regulations and privacy rights

Multi-Factor Authentication

Advanced authentication systems protect against unauthorized access

Role-Based Access Control

Granular permissions ensure users only access data they need

Complete Audit Trails

Comprehensive logging of all system activities and data access

Secure Infrastructure

Enterprise-grade infrastructure with multi-region data centers and 24/7 monitoring

Configurable Hosting Region

We host across multiple regions. The region holding your data is selected to meet your own requirements and the data governance rules that apply in your country or region. The specific region for your tenant is stated in your Data Processing Agreement.

Industry Compliance Standards

Independently verified certifications and compliance frameworks

ISO 27001:2022

ISO 27001:2022 certified (certificate 513272026). The Annex A controls applicable to our certified scope are recorded in our Statement of Applicability.

Certified

GDPR

European General Data Protection Regulation

Compliant

Your Data Never Touches Anyone Else's

Every client on MyCustomsInfo® runs in a completely isolated environment. This is an architectural fact, not a configuration option, not a contractual promise.

Individual Instance Per Client

Every client is provisioned as a completely separate infrastructure instance from day one: dedicated AWS S3 prefix, dedicated PostgreSQL schema with Row Level Security, dedicated document storage namespace, dedicated analytics data catalogue.

Zero Blast Radius

A security incident affecting one client cannot expose any other client's data through any failure mode. Your data and another client's data have never been in the same environment.

Your Own Encryption Key

Every client's data is encrypted with a dedicated AWS Customer Managed Key. Only your instance can decrypt your data. Not shared. Not rotated across clients.

Configurable Hosting Region

We host across multiple regions. The region holding your data is selected to meet your own requirements and the data governance rules that apply in your country or region.

How this differs from standard SaaS security: Most cloud platforms protect client data through access controls within a shared environment. MyCustomsInfo® separates each client's data at the storage layer. There is no shared environment to breach.

Security Through Isolation: Threat Scenario Analysis

Compartmentalised architecture acts as a containment vessel. See how our design limits the impact of real-world attack scenarios.

SQL Injection Vulnerability
Traditional

Entire customer database exposed

MyCustomsInfo®

Single client database affected

Authentication Bypass
Traditional

Access to all client data

MyCustomsInfo®

Access to one client environment

Ransomware Attack
Traditional

Platform-wide encryption

MyCustomsInfo®

One client environment encrypted

Insider Threat
Traditional

Rogue admin accesses all clients

MyCustomsInfo®

Access limited to assigned clients

Frameworks our architecture is designed to support

MyCustomsInfo® holds ISO/IEC 27001:2022 certification. The frameworks listed here describe controls the platform architecture is designed to support. They are not certifications held by MyCustomsInfo®.

GDPR Article 32: Technical measures for security of processing
ISO 27001 (A.13.1): Network security management
NIST CSF “Protect”: Data security protective technologies

Secure Infrastructure & Operations

Our platform is built on enterprise-grade infrastructure with multiple layers of protection and 24/7 monitoring.

Secure Data Centers

Multi-region data centers with physical security and redundancy

24/7 Monitoring

Continuous security monitoring and threat detection systems

Vulnerability Remediation

Vulnerability remediation runs to defined timescales: critical within 24 hours, high within 7 days, medium within 30 days.

Your Data Protection Rights

We take data protection seriously and provide you with full control over your information according to global privacy regulations.

Data Ownership: You retain full ownership of all your data
Data Portability: Export your data anytime in standard formats
Right to Deletion: Request deletion of your personal data
Transparent Processing: Clear information about how we use your data

Security Guarantees

Data Recovery Time< 4 hours
Backup FrequencyReal-time
Data RetentionTerm of contract

Security Questions?

Our security team is available to address any concerns about data protection

US Regulatory Notice. MyCustomsInfo® is an independent compliance auditor. It does not conduct customs business as defined under 19 U.S.C. §1641. The specific tariff classification to be applied to any entry of merchandise is to be determined by a licensed Customhouse broker. MyCustomsInfo® output does not constitute entry preparation, classification advice, or customs broker services. Preparation and filing of Post-Entry Amendments, Post-Summary Corrections, protests, and drawback claims must be performed by a licensed customs broker. US broker records are held in US AWS regions in compliance with 19 C.F.R. §111.23.