Skip to content
Closare — home
Stacked cargo containers and cranes at a working port under overcast sky.

Security and trust

Built to survive a supplier review.

Before a system touches your operational data, someone in IT or security has to sign it off. This page and the documentation pack behind it are written for that reviewer: what is enforced, where the data sits, who can reach it, and what is still planned, so the review can finish without a second call.

What is enforced, not what is intended.

01

Approval gates

Every action is classified before it is switched on. Anything irreversible waits for a named person. Nothing is sent to your clients under an unapproved template.

02

Evidence on every proposal

A proposal carries the data it was built from: timestamps, contract clauses, rates, the documents that were read. A reviewer can reconstruct any decision.

03

Audit trail

What was read, what was proposed, who approved it and what was written back. Exportable, and retained for the period your contract sets.

04

Role-based permissions

Scoped per client desk and per operation. An agent working one client's queue cannot read another's.

05

Scoped credentials

We ask for the narrowest scope that lets a module work, and the scope is recorded alongside the integration.

06

No training on customer data

Your operational data is not used to train shared models. It is processed to run your operation and for nothing else.

Where it sits, how long it stays.

Hosting region
European Union
Data in transit
TLS 1.2 or higher
Data at rest
Encrypted, with field-level encryption on credentials
Retention
Set per contract; operational records default to 24 months
Sub-processors
Listed in full, with notice before any change
Deletion
On request and on termination, with written confirmation

Available on request, before the first call.

Ask once and you receive the whole set. We would rather your reviewer read it early than discover a gap late.

    Data processing agreement Available
    Sub-processor list Available
    Hosting and retention statement Available
    Access and permissions model Available
    Incident response process Available
    Penetration test plan Available
    ISO 27001 roadmap Available

Request the pack at [email protected], or tick it in the enquiry form below.

What applies now, and what is planned.

Applies now

GDPR
Processor obligations, DPA on request
EU data residency
All processing in the European Union
SSO
SAML and OIDC against your identity provider

Planned

Penetration test 2027
First external test
ISO 27001 2028
Certification, not yet held
NIS2 supplier pack 2027
Aligned to the 3 April 2027 deadline

Send this to your reviewer, then talk to us.

If your security team has a questionnaire, send it with the enquiry and we will return it completed rather than scheduling a call to discuss it.

An operational conversation

Your systems. Your constraints.
A clear starting point.

What are you asking for

We use these details to answer your enquiry and for nothing else. See our privacy notice.