Security at Parcelio
Logistics data is sensitive — routes, addresses, payment records. Here's how we protect it.
Encryption everywhere
All traffic is encrypted in transit with TLS. Sensitive fields — payment references, driver documents — are encrypted at rest.
Role-based access
Every console action is scoped to a role. Admins, dispatchers, and finance users only see what their role permits, and every privileged action is audit-logged.
Continuous monitoring
Infrastructure and API traffic are monitored for anomalies around the clock, with automated alerts for unusual access patterns or failed-login spikes.
Data minimization
We collect only what's needed to run deliveries. Driver GPS traces are automatically purged after 90 days.
Resilient infrastructure
The platform runs across redundant infrastructure with automated backups, so a single node failure never means lost delivery data.
Responsible disclosure
Found a vulnerability? Report it to security@parcelio.io — we acknowledge reports within 48 hours and don't pursue legal action against good-faith researchers.
Report a vulnerability
We'd welcome a report. Email security@parcelio.io with steps to reproduce. Please avoid testing against production customer data, and give us a reasonable window to fix an issue before public disclosure.