Security
How Logentic protects your data.
Logentic holds your orders, inventory, shipping labels and carrier accounts. This page explains where that data lives, who can reach it, and how we connect to the services you use.
Sign in · Maison Essentials
Sample data
Infrastructure
Built on audited infrastructure
Logentic runs on Vercel and Supabase. Both are independently audited to SOC 2 Type 2 and certified to ISO 27001.
Vercel
Application hosting
Application servers in US East (Washington, D.C.)
- SOC 2 Type 2
- ISO 27001:2022
The Logentic app runs on Vercel. Vercel's SOC 2 Type 2 attestation covers Security, Confidentiality and Availability.
Supabase
Database, sign-in and file storage
Canada (Central) region, on AWS
- SOC 2 Type 2
- ISO 27001
Your workspace database, user accounts and stored files are in Supabase's Canada (Central) region, which runs on Amazon Web Services.
Where your data is processed
The database, sign-in and stored files sit in Canada. The application servers that handle each request run in Vercel's US East region, and the service providers listed under Subprocessors process the data they need in their own locations.
These certifications belong to Vercel and Supabase. They cover the platforms Logentic runs on, not an audit of Logentic itself.
Data protection
Encrypted on the way and at rest
Connections to Logentic are encrypted, our hosting providers encrypt what they store, and the most sensitive credentials get a second layer from Logentic.
Encrypted in transit
Every connection to the Logentic app uses HTTPS. Plain HTTP is redirected, and browsers are told to refuse unencrypted connections (HSTS).
Encrypted at rest
Vercel and Supabase encrypt the data they store with AES-256.
Credentials encrypted again
API keys, passwords and access tokens you save for carriers and stores are encrypted by Logentic with AES-256-GCM before they are stored. They are never sent back to your browser.
Daily backups
Supabase backs up the Logentic database every day and keeps at least the last 7 days of backups.
How Supabase backups work (opens in a new tab)Card details stay with Stripe
You pay in Stripe Checkout or in Stripe's own payment fields, so full card numbers go to Stripe, never to Logentic. Stripe is certified PCI Service Provider Level 1.
Security at Stripe (opens in a new tab)Your data stays yours
Under the Logentic Shipping Terms you keep the rights to your data and Logentic does not sell it. For 30 days after you leave, you can request a standard export.
Logentic Shipping Terms (opens in a new tab)
Access control
The right people, and only them
Each workspace is kept separate from the others, and inside it every person gets the access their job needs.
Separate workspaces
Row-level security in the database keeps each workspace's records apart. Before the app reads anything, it checks that you are a member of that workspace.
Roles for every job
Eight roles: Company owner, Admin, Manager, Shipping agent, Warehouse staff, Customer service, Finance and Viewer. Owners and admins can turn single permissions on or off for one person and limit them to certain warehouses.
Multi-factor sign-in
You sign in with your email and password, plus a code from an authenticator app once MFA is on. New passwords need at least 12 characters. Owners and admins can require MFA for the whole workspace or for one person.
Role-gated carrier actions
Buying labels, booking pickups and voiding shipments are limited to roles that allow carrier actions. By default, Viewers can see shipments but not change them.
Activity log
Invites, role and permission changes, deactivations and MFA changes are recorded in the workspace Activity log, along with failed syncs and disconnected stores. Deactivate someone and they can no longer sign in, while their history stays.
Logentic staff access
Logentic's internal support tools use their own staff roles and permissions, kept apart from your workspace roles. An owner or admin role in a workspace never opens those tools.
Integrations
Safe connections to your stores and carriers
You decide what Logentic connects to, and incoming messages are verified before Logentic acts on them.
OAuth for your apps
Shopify, Lightspeed Retail, Gmail and Slack can connect through their own OAuth approval screens, so you approve access on their side and never hand us a password.
Carrier credentials
Carrier accounts connect with the credentials your carrier issues, using OAuth where the carrier supports it, as UPS and FedEx do. By default, only owners, admins and managers can add or change a connection, and the app never shows the full credential again.
Verified webhooks
Messages from Shopify, Stripe, carriers and other services are checked against the sender's signature or shared secret before Logentic acts on them. Stale deliveries are rejected and repeats are recognized, so a replayed message is not applied twice.
Shopify privacy requests
Logentic handles Shopify's mandatory privacy webhooks: customer data requests, customer data redaction, and shop data redaction after an uninstall.
AI and your data
Ask Logan works inside your workspace
Ask Logan, the assistant in Logentic, answers from your own workspace. Here is what it works from and what stays out.
What Ask Logan works from
- Live records from the workspace you are signed in to, never another one
- Logentic's product help
- Procedures your team adds in Settings → Ask Logan → Knowledge
- Files you attach, kept in private storage for your workspace
What stays out
- Other companies' data
- Secrets, webhook keys and stored credentials
- Training of public AI models: the Logentic Shipping Terms commit that we will not use your data, prompts or AI output to train publicly available foundation models, or let model providers do so
Ask Logan runs on OpenAI's API. Text requests are sent with OpenAI's response storage turned off. By default, OpenAI does not use API data to train its models. OpenAI's API platform holds a SOC 2 Type 2 report and ISO/IEC 27001:2022 certification.
Availability
Status and incidents in the open
Logentic publishes live system status, and automated alerts tell our engineers when something fails.
Public status page
Live status and uptime history for each part of Logentic. Subscribe for updates or report a problem.
- API
- WMS
- Website / App
- Carriers
- Integrations
- Auth
Automated alerts
Application errors are tracked, and failed background jobs, database errors and carrier failures send alerts to the engineering team.
Tested before release
Code changes go through an automated test suite before release, and releases are published in the in-app changelog.
Subprocessors
Who processes data for Logentic
The main service providers Logentic uses to run the platform.
| Provider | What we use it for |
|---|---|
| Vercel | Application hosting |
| Supabase (on AWS) | Database, sign-in and file storage |
| Stripe | Subscription, wallet and card payments |
| OpenAI | Ask Logan and other AI features |
| Resend | Sign-in, invite and notification emails |
| Twilio | Text messages sent by your automations |
| Sentry | Error monitoring |
| PostHog | Product analytics inside the app |
| Jam | Screen recordings you choose to send with a bug report |
Services you connect yourself, such as Shopify, Lightspeed, Gmail, Slack and your carriers, receive the data they need to work under their own terms.
Questions about this list? Contact usQuestions
Need more detail for your review?
Ask us about anything on this page, including the questions on your security review.