Logentic

Security

How Logentic protects your data.

Logentic holds your orders, inventory, shipping labels and carrier accounts. This page explains where that data lives, who can reach it, and how we connect to the services you use.

Sign in · Maison Essentials

Sample data

Infrastructure

Built on audited infrastructure

Logentic runs on Vercel and Supabase. Both are independently audited to SOC 2 Type 2 and certified to ISO 27001.

Vercel

Application hosting

Application servers in US East (Washington, D.C.)

  • SOC 2 Type 2
  • ISO 27001:2022

The Logentic app runs on Vercel. Vercel's SOC 2 Type 2 attestation covers Security, Confidentiality and Availability.

Supabase

Database, sign-in and file storage

Canada (Central) region, on AWS

  • SOC 2 Type 2
  • ISO 27001

Your workspace database, user accounts and stored files are in Supabase's Canada (Central) region, which runs on Amazon Web Services.

Where your data is processed

The database, sign-in and stored files sit in Canada. The application servers that handle each request run in Vercel's US East region, and the service providers listed under Subprocessors process the data they need in their own locations.

These certifications belong to Vercel and Supabase. They cover the platforms Logentic runs on, not an audit of Logentic itself.

Data protection

Encrypted on the way and at rest

Connections to Logentic are encrypted, our hosting providers encrypt what they store, and the most sensitive credentials get a second layer from Logentic.

  • Encrypted in transit

    Every connection to the Logentic app uses HTTPS. Plain HTTP is redirected, and browsers are told to refuse unencrypted connections (HSTS).

  • Encrypted at rest

    Vercel and Supabase encrypt the data they store with AES-256.

  • Credentials encrypted again

    API keys, passwords and access tokens you save for carriers and stores are encrypted by Logentic with AES-256-GCM before they are stored. They are never sent back to your browser.

  • Daily backups

    Supabase backs up the Logentic database every day and keeps at least the last 7 days of backups.

    How Supabase backups work (opens in a new tab)
  • Card details stay with Stripe

    You pay in Stripe Checkout or in Stripe's own payment fields, so full card numbers go to Stripe, never to Logentic. Stripe is certified PCI Service Provider Level 1.

    Security at Stripe (opens in a new tab)
  • Your data stays yours

    Under the Logentic Shipping Terms you keep the rights to your data and Logentic does not sell it. For 30 days after you leave, you can request a standard export.

    Logentic Shipping Terms (opens in a new tab)

Access control

The right people, and only them

Each workspace is kept separate from the others, and inside it every person gets the access their job needs.

  • Separate workspaces

    Row-level security in the database keeps each workspace's records apart. Before the app reads anything, it checks that you are a member of that workspace.

  • Roles for every job

    Eight roles: Company owner, Admin, Manager, Shipping agent, Warehouse staff, Customer service, Finance and Viewer. Owners and admins can turn single permissions on or off for one person and limit them to certain warehouses.

  • Multi-factor sign-in

    You sign in with your email and password, plus a code from an authenticator app once MFA is on. New passwords need at least 12 characters. Owners and admins can require MFA for the whole workspace or for one person.

  • Role-gated carrier actions

    Buying labels, booking pickups and voiding shipments are limited to roles that allow carrier actions. By default, Viewers can see shipments but not change them.

  • Activity log

    Invites, role and permission changes, deactivations and MFA changes are recorded in the workspace Activity log, along with failed syncs and disconnected stores. Deactivate someone and they can no longer sign in, while their history stays.

  • Logentic staff access

    Logentic's internal support tools use their own staff roles and permissions, kept apart from your workspace roles. An owner or admin role in a workspace never opens those tools.

Integrations

Safe connections to your stores and carriers

You decide what Logentic connects to, and incoming messages are verified before Logentic acts on them.

  • OAuth for your apps

    Shopify, Lightspeed Retail, Gmail and Slack can connect through their own OAuth approval screens, so you approve access on their side and never hand us a password.

  • Carrier credentials

    Carrier accounts connect with the credentials your carrier issues, using OAuth where the carrier supports it, as UPS and FedEx do. By default, only owners, admins and managers can add or change a connection, and the app never shows the full credential again.

  • Verified webhooks

    Messages from Shopify, Stripe, carriers and other services are checked against the sender's signature or shared secret before Logentic acts on them. Stale deliveries are rejected and repeats are recognized, so a replayed message is not applied twice.

  • Shopify privacy requests

    Logentic handles Shopify's mandatory privacy webhooks: customer data requests, customer data redaction, and shop data redaction after an uninstall.

AI and your data

Ask Logan works inside your workspace

Ask Logan, the assistant in Logentic, answers from your own workspace. Here is what it works from and what stays out.

What Ask Logan works from

  • Live records from the workspace you are signed in to, never another one
  • Logentic's product help
  • Procedures your team adds in Settings → Ask Logan → Knowledge
  • Files you attach, kept in private storage for your workspace

What stays out

  • Other companies' data
  • Secrets, webhook keys and stored credentials
  • Training of public AI models: the Logentic Shipping Terms commit that we will not use your data, prompts or AI output to train publicly available foundation models, or let model providers do so

Ask Logan runs on OpenAI's API. Text requests are sent with OpenAI's response storage turned off. By default, OpenAI does not use API data to train its models. OpenAI's API platform holds a SOC 2 Type 2 report and ISO/IEC 27001:2022 certification.

Availability

Status and incidents in the open

Logentic publishes live system status, and automated alerts tell our engineers when something fails.

Public status page

Live status and uptime history for each part of Logentic. Subscribe for updates or report a problem.

  • API
  • WMS
  • Website / App
  • Carriers
  • Integrations
  • Auth
  • Automated alerts

    Application errors are tracked, and failed background jobs, database errors and carrier failures send alerts to the engineering team.

  • Tested before release

    Code changes go through an automated test suite before release, and releases are published in the in-app changelog.

Subprocessors

Who processes data for Logentic

The main service providers Logentic uses to run the platform.

Who processes data for Logentic
ProviderWhat we use it for
VercelApplication hosting
Supabase (on AWS)Database, sign-in and file storage
StripeSubscription, wallet and card payments
OpenAIAsk Logan and other AI features
ResendSign-in, invite and notification emails
TwilioText messages sent by your automations
SentryError monitoring
PostHogProduct analytics inside the app
JamScreen recordings you choose to send with a bug report

Services you connect yourself, such as Shopify, Lightspeed, Gmail, Slack and your carriers, receive the data they need to work under their own terms.

Questions about this list? Contact us

Questions

Need more detail for your review?

Ask us about anything on this page, including the questions on your security review.