Security and data protection
This page summarizes ContainerHub's security posture for procurement, IT, and compliance teams evaluating the platform, and for administrators already running it. For full legal terms, see the privacy policy.
Encryption
- In transit: all connections to the platform use TLS.
- At rest: stored data (database and files) is encrypted at rest by our infrastructure providers.
Cross-company isolation (multi-tenant)
ContainerHub is a multi-tenant platform: each company (depot) can only access its own data. Isolation is enforced in two layers — at the application level (every query is scoped by company) and at the database level, with Row-Level Security policies.
Role-based access control (RBAC)
- Distinct roles by function: administration, operations, inspection, sales/commercial, and external clients with reduced visibility.
- Each person should have their own account; avoid shared logins.
- Access and roles can be reviewed and revoked at any time from your company's administration settings.
Audit logging
Key actions on containers, gate movements, inspections, repairs, and quotations are logged in a company-scoped audit trail for operational and compliance traceability.
Backups
Database backups are managed by our infrastructure provider (Supabase) as part of standard platform operations.
Data retention
- Operational data is retained while the account is active.
- After account deletion, anonymized records are retained for up to 12 months for audit purposes.
- Billing records are retained for 7 years, as required by applicable tax law.
See the privacy policy for full details.
Subprocessors
ContainerHub runs on third-party infrastructure, all under data processing agreements (DPAs):
- Vercel — application hosting.
- Supabase — managed PostgreSQL database and file storage.
- Stripe — payment processing.
- OpenRouter — AI model provider for the assistant (do not submit sensitive personal data via the AI chat).
International transfers
When processing occurs outside the European Economic Area, we apply appropriate safeguards (e.g., Standard Contractual Clauses approved by the European Commission).
Data Processing Agreement (DPA)
Business customers can request a signable DPA as part of the contracting process.
Certifications
ContainerHub does not currently hold its own SOC 2 or ISO 27001 certification. Our infrastructure providers (Vercel, Supabase, Stripe) maintain their own security certifications, publicly documented on their sites. If your procurement process requires additional documentation, contact us.
Incident management
In the event of a security incident affecting customer data, we notify administrators of the affected company and, where required by law, the relevant authorities, per the timelines in our privacy policy.
AI and operational decisions
AI features are designed to assist teams, not replace final human checks. Always review suggested results before confirming critical actions.
Recommended practices for your team
- Use strong passwords and update access when responsibilities change.
- Share operational links only with the people involved in the move.
- For external clients, use the client portal with limited visibility.
- If you export data, store files in company-controlled locations.
Privacy, security, or compliance questions
For legal or compliance documentation specific to your organization, see the privacy policy and the official contacts published there.

