Security

Built for trust.

Chain-of-custody documentation only works if the chain is unbroken. Here's how we protect it.

šŸ”’

HTTPS everywhere

All traffic encrypted in transit via TLS 1.3. No exceptions — from first login to PDF download.

šŸ—„ļø

Encrypted at rest

All data stored encrypted via Supabase (AES-256). Photos, shipment data, and user records.

šŸ‘„

Role-based access

Admins, handlers, viewers — each role sees only what it needs. Enforced at the database level with row-level security.

šŸ”—

Secure tracking links

64-character random tokens. Expiry and revocation supported. No login required for viewers, no sensitive data exposed.

šŸ‡ŖšŸ‡ŗ

EU data storage

GDPR-compliant. All data stored in EU data centers (Supabase EU region). No data leaves the EU.

šŸ“‹

Full audit trail

Every action logged with timestamp, user, and context. Immutable once recorded. Available for insurance and legal use.

Immutable chain of custody

Once a project is marked complete, the chain of custody is permanently locked. No step can be edited, deleted, or backdated. Every record shows the exact timestamp it was created — not when it was approved.

This is intentional. The value of chain-of-custody documentation comes from its inability to be altered after the fact.

GDPR compliant

ArtShipLink is operated by LUXEE Tech OÜ, an Estonian company. All data is stored in EU data centers and processed under GDPR. You control your data — request export or deletion at any time.