Trust & Compliance Credentials
The evidence behind every claim we make
Customs data is sensitive commercial intelligence. This page consolidates our security architecture, regulatory credentials, and operational principles so your procurement and information security teams have everything in one place.
Security Architecture
Four pillars protecting your customs data from ingestion to output.
Per-Tenant Data Isolation
Every client operates in a dedicated, isolated database environment. Your declarations, origin certificates and broker worksheets are never co-mingled with another importer’s data.
How our architecture worksAWS KMS Customer-Managed Keys
All data encrypted at rest using AWS Key Management Service with customer-managed keys (CMK). All data in transit is encrypted using TLS 1.2 or higher. You retain control of your encryption keys.
View security detailsISO 27001:2022 Certified
ISO 27001:2022 certified (certificate 513272026). Certified scope: the provision of automated customs technology, compliance services and strategic consultancy to all sectors. The Annex A controls applicable to our certified scope are recorded in our Statement of Applicability.
View data governanceUK GDPR Article 28 Compliant
Full Data Processing Agreement available from day one. Sub-processor list on request. The specific region for your tenant is stated in your Data Processing Agreement.
Data governance policyThe MyCustomsInfo® platform runs on Amazon Web Services. Customer data is held there and nowhere else. Microsoft 365 and Entra ID are used for CustomsPlus® internal business operations and staff identity. They do not hold or process customer data.
Regulatory Credentials
Every claim on this site is backed by a published ruling, a documented process, or a verifiable registration.
19 USC §1641 Compliance
Independent Compliance Auditor
MyCustomsInfo® identifies duty recovery opportunities. Your licensed customs broker acts on our findings. We never prepare, file, or submit anything to CBP. We identify. Your broker acts.
UK & EU Regulatory
ICO Registration
Registered with the UK Information Commissioner’s Office for data processing activities related to customs compliance auditing and duty recovery.
AEO Posture
Platform architecture and access controls designed to support Authorised Economic Operator (AEO) status requirements for clients holding or pursuing AEO certification.
Operational Principles
All data in transit is encrypted using TLS 1.2 or higher. Data at rest encrypted with AES-256 via AWS KMS CMK.
Strictly authorised human access only. Every interaction logged and traceable.
Mutual NDA and Data Processing Agreement from day one of every engagement
We host across multiple regions. The region holding your data is selected to meet your own requirements and the data governance rules that apply in your country or region.
Vulnerability remediation SLAs (Critical 24h, High 7 days, Medium 30 days)
What MyCustomsInfo® Does. And Does Not Do.
What We Do
- • Audit customs entries against source documents
- • Identify duty recovery opportunities across regimes
- • Produce structured findings with recommended actions
- • Quantify overpayment exposure per entry and per regime
- • Deliver audit packs to your licensed customs broker
What We Never Do
- • Prepare, file, or submit entries to CBP
- • Determine or confirm HTS classifications
- • Act as your customs broker
- • Complete CBP Form 5106 or drawback claims
- • Make decisions that require a broker licence
See our full compliance statement.
Team Credentials
Every member of the MyCustomsInfo® team holds formal certification from the Chartered Institute of Export & International Trade (CIET) at Level 4 or Level 5.
Dominic McGough
Founder & CEO
CIET Level 5Sally McGough
Operations Director
CIET Level 5Kian Keong Tan
Senior Customs Analyst
CIET Level 4Mary McGough
Customer Operations
CIET Level 4Conor Anderson
Trade Compliance Specialist
CIET Level 5Detailed Documentation
Each area of our trust framework is documented in detail. Share these pages directly with your procurement, legal, or information security teams.
Data Architecture
Per-tenant isolation, blast radius containment, zero data co-mingling
Data Governance
Data residency commitments, ISO 27001:2022 certification
Data Security
AWS infrastructure, access controls, encryption standards
Confidentiality
We publish client results in anonymised form only, and we work under mutual NDA. Named references are available during procurement, with the client’s written consent.
US regulatory position
Our formal US regulatory position.
Implementation Guide
30-day onboarding roadmap: data handling, legal pack, effort split
Need more detail for your procurement team?
We provide our ISO 27001:2022 certificate (513272026) and Statement of Applicability on request, along with our Data Processing Agreement and an architecture overview.
+44 151 808 0103 (UK) · +1 (312) 728-4277 (US) · [email protected]
