Supercargo

Security

Seven claims, and the four that are not true yet

Sending your customs data to a small company you have never met is a real risk, and telling you we take security seriously is worth nothing. So every claim here is written to be verified by you, from outside — and the ones that describe how the platform is architected rather than something you can check today are in their own section, marked as such.

The strongest one is first, and it is the only one that does not depend on our conduct at all: in the United States your entry data reaches us because you scheduled a CBP report to an address of your choosing, and it stops when you say so.

Checkable today

Three claims you can test without our help

01 Your entry data comes from a report you schedule yourself

Check it: create the ACE account before you ever speak to us. The report exists whether or not you become a customer, and five years of your own entry lines are already sitting behind it (19 CFR 163.4).

You enrol in CBP’s ACE Secure Data Portal yourself, as the importer of record. CBP’s own published guide (Publication 5228-1025, October 2025) puts it at about ten minutes. Inside your own account you schedule the ITRAC Entry Summary Line Tariff Details report as a recurring CSV, sent to an address you choose — which can be ours. You delete the schedule and it stops. There is no power of attorney, no filer code, no shared password, and no CBP credential of yours anywhere in our systems. The report is produced by the government, inside your account, on your instruction, and the only thing we ever hold is the CSV you decided to send us.

Why we refused the obvious alternative

The tidier build is an ABI connection with a filer code, so entry data flows to us automatically and nobody schedules anything. We are not doing that, and the reason is not cost. An ABI filer sits in the transmission path to CBP, and that path is customs business under 19 CFR 111.1. CBP has held a software vendor to be conducting customs business even where a licensed US broker filed every entry (HQ H068278), and has rejected an “advisory only” label as a cure for it (HQ H290535). Licensure is not a fallback: 19 CFR 111.11(a)(1) requires the individual licensee to be a US citizen, and our founder is not one. So the scheduled report is not a cheap substitute for a real integration. It is the only architecture that keeps us permanently outside the loop between you and CBP — and it happens to be a better security story than the integration would have been.

The snag, which you should hear from us first

If your customs broker has already associated your importer number with their own ACE top-level account, you cannot create one of your own until that is unwound — and the verification code goes to the point-of-contact email on your CBP Form 5106, which is very often the broker’s inbox rather than yours. That is the ordinary state of a long-standing broker relationship, not a fault in your account. It is also your relationship to unwind, not ours, and it is the first thing we check before taking your money. There is no way around it from our side: ACE “Service Provider” sub-accounts carry no Run Reports permission at all, so no third party can pull your entries on your behalf even if you wanted one to. That constraint is exactly why the architecture is what it is.

02 Amazon never grants us permission to see your customers

Check it: Amazon publishes the full role-to-operation mapping today, and the consent screen enumerates every role we ask for before you approve anything. Both are readable without us.

We will hold six non-restricted roles and no others. We did not request Direct-to-Consumer Shipping, Professional Services, Tax Invoicing or Tax Remittance — the four roles that carry personal data — so buyer names, addresses and contact details are not something we have chosen not to look at. They are something Amazon will not give us. Adding a role later would force every existing customer to re-authorise, which is precisely why the list is published here before there is anyone to publish it to.

04 Self-hosting would make your security worse

Check it: read Amazon’s Acceptable Use Policy §3.1 and §3.2. We are not permitted to hand you our credentials, and we will not pretend otherwise to win a deal.

People ask for this, and we understand why. But the only version of self-hosting that Amazon’s rules actually permit is one where YOU register your own developer application, wait weeks for your own roles to be approved, and then become the permanent custodian of a client secret — with no rotation tooling and no revocation screen. Amazon’s Data Protection Policy requires credentials to be rotated at least annually and forbids hardcoding them. A customer-held secret on a customer-run box fails both. We are asking you to hold fewer secrets, not more. Note that claim 01 already gives you the thing self-hosting is usually asked for: the customs data path has no credential in it anywhere.

Architecture

Four commitments about how it is built

These four are architectural rather than checkable from outside — you cannot verify another tenant’s isolation by looking at our website, and any company claiming otherwise is describing something you have no way to test. They are published in advance, in specifics rather than adjectives, so they can be held against us. The audit needs none of them: it runs on documents you send and returns a written reconciliation, with no account and nothing stored on your behalf.

03 There is no API key

Check it: the revoke button is in your Seller Central account right now, whether or not you are our customer.

Authorisation is an OAuth click inside Seller Central. You never hold, type, paste, store or rotate a secret — there is no field to put one in, because there is nothing to put — and you revoke it yourself in two clicks at Apps & Services → Manage Your Apps, without asking us and without telling us. Amazon’s consent screen, not our marketing, is what enumerates the access.

05 Your data will be in its own database, not a row in ours

Check it: ask us for the schema and the provisioning migration as they stand today. We will send them, and you can hold the running system to them when you onboard.

One Postgres database, one database role and one AES-256-GCM data-encryption key per customer, each key wrapped by a master key held separately. There will be no tenant_id column to get a WHERE clause wrong on, because there will be no shared table. A multi-tenant competitor cannot retrofit this cheaply, which is rather the point — and it is far easier to build this way from zero customers than to migrate to it from a thousand.

06 Your export will already be in your own bucket

Check it, once you are a customer: the first dump should reach your bucket within seven days of connecting, which is before your second invoice. If it does not, you have a contractual right to leave with a pro-rata refund.

From launch, a full database dump will land every week in the S3 or R2 bucket you nominate, encrypted to your own key. On every tier, at no extra cost, for the life of the subscription. The point is that when you leave you already have your data — nothing to request, no ticket to raise, no 30-day clock to run down. It is unconditional deliberately: an export you have to ask for is a retention lever, and we would rather not own one.

07 These modules will keep working if Amazon ever cuts us off

Check it, and hold us to the list: it is published here before the software exists precisely so that it cannot be quietly widened afterwards.

Landed cost, duty and trade remedies, the purchase-order ledger, customs-entry reconciliation, container tracking and cash flow are designed to run entirely on your own documents and on published government tariff data, in a physically separate database schema from anything Amazon-derived. If our Amazon access were suspended, those screens would not notice. The Amazon-derived screens — units sold, fees, ad spend, net proceeds, stock position — would stop. That list is exhaustive and we will not add to it quietly.

The detail

Where things will run and how long they will be kept

What we will never hold

A CBP credential, an ACE password, a filer code, a power of attorney, or any ability to transmit anything to a customs authority on your behalf. Not by policy — by architecture. See claim 01, and clause 10 of the terms, where it is a contract term rather than a paragraph on a marketing page.

Location

Dedicated hardware in the EU (Germany). Nothing of yours on a US-hosted system.

The application and database will run on dedicated hardware in the EU (Hetzner, Falkenstein, Germany), operated by JG Core Ltd. Static marketing pages are served from Vercel’s edge network today. US customers should know this plainly: your entry-line CSV and your commercial invoices will be processed in Germany by an English company, and nothing of yours will sit on a US-hosted system. That is a deliberate choice and we would rather you weighed it than discovered it.

Retention

Raw Amazon data 18 months, monthly aggregates 36, your own documents until you delete them.

Raw Amazon-derived data will be retained for 18 months, which is Amazon’s own ceiling under its Data Protection Policy. Month-level aggregates derived from it will be kept for 36 months, because restock forecasting needs more than one seasonal cycle; the justification for that is available on request. Your own documents — commercial invoices, entry summaries, purchase orders — are yours and are kept until you delete them.

Subprocessors

Hetzner, Vercel, Stripe, Resend, Cloudflare — and notice before we add one that touches your data.

Hetzner (hosting, EU), Vercel (static marketing site, no customer data), Stripe (payments; we never see a card number), Resend (transactional email), Cloudflare (network). A current list with purposes is in the privacy notice. We will tell you before adding one that touches customer data.

Reporting a vulnerability

Email us with “security” in the subject. Acknowledged within one business day.

Email contact@getsupercargo.com with “security” in the subject. We will acknowledge within one business day. We do not currently run a paid bounty, we will not threaten you, and we will credit you if you want to be credited.

Still not comfortable?

Then connect nothing. Send us one entry summary — CBP Form 7501, or the single line from your ITRAC export — and the commercial invoice behind it, and we will show you the working on your own numbers with no account, no marketplace access and no software at all.

Start with the auditTry the demo first