Back to SwiftConfirm

Security Overview

Last updated: August 5, 2026

Our approach

In freight, your rates and your customer list are your business. SwiftConfirm, operated by Alpoz Technologies Inc., is built so they stay private. This page describes how, in enough detail for your IT or security reviewer. Questions or anything missing? Write to [email protected].

Tenant isolation

Every record in SwiftConfirm belongs to exactly one company, enforced at the database layer with row-level security in addition to application checks. Company identity comes from the authenticated session on every request, never from anything a client sends. No plan, screen, or API path returns another company's data.

Encryption

All traffic is encrypted in transit with TLS. Data is encrypted at rest by our database provider (AES-256). On top of that, personal contact details are additionally encrypted at the application level, so they are unreadable even with direct database access.

Access control and auditing

Team roles control what each member can see and do, enforced server-side on every request. Sensitive actions (creating, changing, and deleting records; sending documents; sign-ins) are written to an audit log recording who did what and when. Administrative access to our systems is limited to named individuals with multi-factor authentication.

Backups and continuity

Your data is backed up automatically every day, and restore procedures are tested, not assumed. Application infrastructure is monitored around the clock with automated alerting.

Auto-fill and your documents

When you paste a carrier email or upload a PDF, the details are extracted to pre-fill a load form that you review and confirm before anything is sent. Nothing goes out without your approval. The text is processed solely to produce that result, is not stored by the processing provider beyond the request, and is never used to train models. The in-app assistant answers only from our product documentation and your own account's data.

Payments

Billing runs entirely through Stripe, a PCI DSS Level 1 certified processor. Card numbers never touch SwiftConfirm's servers.

Subprocessors

We use a small set of established infrastructure providers to run the service. A current subprocessor list is available on request at [email protected].

Your data, your exit

You can export all of your records as CSV files from your account settings at any time, free. On account closure we delete your data in the normal course of operations after a reasonable export window. There is no lock-in and no exit fee.

Certifications and roadmap

SwiftConfirm runs entirely on SOC 2-compliant infrastructure providers. A formal SOC 2 examination of SwiftConfirm itself is on our roadmap as our customer base grows; the controls described on this page are how we operate today.

Reporting a vulnerability

If you believe you have found a security issue, email [email protected] with enough detail to reproduce it. We acknowledge reports within one business day, keep you informed while we fix confirmed issues, and will not pursue action against good-faith research that respects our users' data.