Protecting the Data You Trust Us With
Access control, monitoring and controlled processing environments — because outsourcing your back office means handing over your financial records.
Why this page exists
You are not buying a security product. You are asking whether we can be trusted.
Outsourcing your back office means giving an external team access to carrier contracts, customer records, invoice data and often your accounting system. That is a genuine exposure, and it deserves a straight answer rather than a page of icons.
What follows is how we handle it — who gets access to what, where work is performed, what happens if something goes wrong, and what your compliance team can expect when they assess us. If your security questionnaire asks something not covered here, ask us directly and we will answer it in writing.
Access control
Named people, scoped permissions.
The most common failure in outsourced operations is not a breach. It is shared logins and access that outlives the person who needed it.
- Access granted per named individual, never shared credentials
- Permissions scoped to the records the work requires
- Credentials issued by you and held individually
- Every action in your system attributable to a person
- Access reviewed periodically and revoked on team change
- Immediate revocation when someone leaves the engagement
Processing environment
Where the work actually happens.
Work is performed in controlled facilities with restricted physical access, on managed devices rather than personal ones. Wherever the engagement allows, our teams work inside your systems rather than copying data out — which means your records stay under your control, your retention policy and your audit trail.
That is not only a security preference. It is also why there is usually nothing to return when an engagement ends.
Physical controls
Restricted floors, managed equipment.
- Badge-controlled access to processing areas
- Managed workstations, not personal devices
- Clean-desk operation on client-data floors
- Visitor and contractor access logging
Data handling
Encrypted in transit, minimised at rest.
- Encrypted transfer for any data movement
- Work inside client systems wherever possible
- Working copies minimised and time-limited
- Return or destruction on your instruction at exit
Monitoring
Activity logged, anomalies escalated.
- System and access activity logging
- Anomaly detection and escalation
- Endpoint protection on managed devices
- Regular vulnerability assessment
Compliance & assurance
What your compliance team can expect.
Our information security practices are structured around recognised standards, and we complete vendor security assessments as part of onboarding. Tell us what your compliance team requires and we will work through their questionnaire with them directly rather than pointing at a badge.
Contractual commitments — confidentiality, incident notification timelines, data handling at exit — are agreed before work begins rather than left to policy documents nobody reads.
If something goes wrong: you are notified. Our incident response covers containment, assessment of what was affected, and a written account of what happened and what changed as a result. Notification timelines are set in the engagement contract rather than left open-ended.
By sector
What we are protecting varies.
Each of these covers the wider back office scope for that segment.
Freight Payment Companies
Carrier bank details, payment instructions, rate contracts.
3PL Providers
Client inventory data, rate cards, order records.
Custom House Brokers
Importer records, valuation data, entry documentation.
Freight Forwarders
Customer contracts, shipment records, agent agreements.
NVOCC Operators
Bills of lading, tariff records, shipper details.
Trucking Companies
Driver records, settlement data, customer rate agreements.
Common questions
The questions procurement actually asks.
Who can see our data?
Only the named team assigned to your account, with access scoped to the systems and records their work requires. Access is granted per person, reviewed periodically, and revoked when someone leaves the team or the engagement.
Where is our data processed?
Work is performed in controlled processing facilities with restricted physical access. Wherever possible we work inside your own systems rather than copying data out, which means your records stay under your control and your retention policy.
How do you handle system access credentials?
Credentials are issued by you, held individually rather than shared, and never stored outside approved systems. Named-user access means every action in your system is attributable to a specific person.
What happens if there is a security incident?
You are notified. Incident response covers containment, assessment of what was affected, and a written account of what happened and what changed as a result. Notification timelines are agreed in the engagement contract rather than left open.
What happens to our data when the engagement ends?
Access is revoked and any working copies are returned or destroyed to your instruction, with confirmation provided. Where we have worked inside your systems there is nothing to return, which is one reason we prefer that model.
Can you complete our security questionnaire?
Yes. Vendor security assessments, questionnaires and due diligence requests are handled as part of onboarding. Tell us what your compliance team needs and we will work through it with them directly.
Security questionnaire to work through?
Send it over. We would rather answer your compliance team's questions properly at the start than discover a gap halfway through an engagement.