Verified user identity
The application accepts user and tenant identity only from a trusted authentication edge that removes caller-supplied identity headers before injecting verified values.
Security
The first MVP is designed around verified identity, tenant isolation, least-privilege service access and auditable activity.
The application accepts user and tenant identity only from a trusted authentication edge that removes caller-supplied identity headers before injecting verified values.
Shipment reads, lists, knowledge records and audit events are partitioned by tenant. Cross-tenant reads are treated as not found.
Calls to CargoGoWhere use short-lived signed assertions and a dedicated secret rather than sharing public or unrelated internal credentials.
Tracking and retrieval actions retain user, tenant and request correlation details to support troubleshooting and review.
Operating principles
Existing pilot organisations should report concerns through their established onboarding contact and include “Security” in the subject or first line. Provide the affected URL and reproduction details, but do not include live credentials, customer shipment data or other sensitive information in the initial message.
General contact guidance is available on the contact page.