Security & Trust

Last updated: 12.03.2026

Freiority is built with a security-first mindset. We follow security‑aligned practices consistent with ISO 27001 and SOC 2 frameworks. Our platform combines technical encryption with rigorous identity verification and privacy-preserving data handling to protect the global freight ecosystem.

Identity Verification (KYC)

Every Freight Forwarder undergoes a multi-step KYC process, including business license verification and regulatory compliance checks before being allowed to quote.

PII Protection & "Soft Reveal"

Customer contact details are redacted by default. Sensitive information is only disclosed to a service provider after a formal quotation is approved by the customer.

Strict Data Validation

All API interactions use strict schema validation (Zod) and type-safe protocols to prevent injection attacks and ensure the integrity of freight data.

Comprehensive Audit Logs

We maintain immutable system audit trails for all sensitive actions, providing complete transparency and forensic accountability for administrative and user events.

Encryption Standards

TLS 1.2+ for data in transit and AES-256 database-level encryption at rest. Sensitive keys are managed via server-side environment isolation.

PCI-Compliant Payments

All financial transactions are processed by PCI‑DSS Level 1 providers (e.g., Razorpay). We never store or transmit full card details on our servers.

Privacy by Design

Freiority operates as a technology intermediary. Our architecture ensures that freight service providers can only access anonymised enquiry information during the discovery phase. This protects the privacy of importers and exporters while allowing forwarders to provide accurate, competitive quotes.

Responsible Disclosure

If you believe you have discovered a security issue, please contact our security team atsecurity@freiority.com. Provide sufficient detail to reproduce the issue. We prioritize security reports and will investigate promptly.

Compliance Alignment

References to ISO 27001, SOC 2, GDPR, and PCI DSS indicate our commitment to aligning with global industry standards and our reliance on certified infrastructure and payment providers. Formal certification status is maintained by our underlying infrastructure and payment partners.