top banner main image
AfterShip Shipping is an official TikTok Shipping partner. Get first month free
Contact us
aftership trust centrepng v

Trusted by the world’s biggest brands

socii
iso
gdpr
center for internet security cis
owasp
Contact us for more information
Security and Privacy at AfterShip Mobile

The AfterShip Services are hosted on Google Cloud Platform and Amazon Web Service in the United States of America and are protected by security and environmental controls. Google Cloud Platform and Amazon Web Service regularly undergo independent verification of security, privacy, and compliance controls. Additional details are available at:

AfterShip configures the firewalls on the production environment according to industry best practices and monitors unauthorized intrusions' services. AfterShip also uses Cloudflare WAF to block cyber-attacks. AfterShip performs automated vulnerability scans on the production environment and remediates any findings that present a risk to our environment. Additionally, AfterShip undergoes annual third-party penetration testing. A bug bounty program through HackerOne is also maintained, where security researchers are invited to submit vulnerabilities to AfterShip throughout the year. Additionally, the security review process facilitated by the security team is an integral part of AfterShip’s development lifecycle and the industry security coding and review practices are followed.

AfterShip regularly performs security awareness training for all staff. AfterShip also offers 24/7 security monitoring and incident response.

Highlights

  • Audit logging
  • Multi-factor authentication (MFA/2FA)
  • Role-based access control (RBAC)
  • Single sign-on (SSO)
  • Strong password requirements 
Product Security
Data Security

Highlights

  • Access monitoring 
  • Routine database backups and recovery practices
  • Data breach notifications made to customers within the time limits established under the GDPR
  • Data collection and processing per user instructions
  • Data erasure per user instructions or according to established retention periods
  • Encryption-in-transit (TLS 1.2) and encryption-at-rest (AES-256)

Highlights

  • Annual third-party penetration tests
  • Automated vulnerability scanning and remediation
  • Bug bounty program
  • Cloudflare WAF to block cyber-attacks
  • Code analysis
Application Security
Infrastructure Security

Highlights

  • 24/7 proactive monitoring and incident response
  • Business continuity and disaster recovery controls
  • Services hosted on AWS and Google Cloud in the United States

Highlights

  • Employee access to platforms controlled through SSO and MFA/2FA
  • Firewalls configured according to industry best practices
  • Intrusion detection and protection systems
  • Security Information & Event Management (SIEM)
  • Virtual Private Cloud
Network Security
Corporate Security

Highlights

  • Asset management practices
  • Crisis Management and Information Security Incident Management policies
  • Email protection
  • ISO 27001-based ISMS
  • HR background checks for all new hires
  • Onboarding and subsequent annual information security trainings for all employees

Overview and Data Protection Law Basics

European-Specific Data Privacy Information

AfterShip’s DPO, GDPR Representative, and Employees

AfterShip Process for the Implementation of Rights

To ensure that the rights described in Section 2 are respected, AfterShip has implemented the following procedures:

Data Protection Rights

Data subjects have a number of rights under Applicable applicable data protection laws.

If you believe you have found a security vulnerability in an AfterShip application, the AfterShip platform, or our infrastructure that could harm AfterShip or anyone who uses AfterShip, contact both [email protected] and [email protected].

For questions related to personal data or privacy, or for data subject requests or data controller requests, contact [email protected].

For questions related to account login, account security, or billing, visit our help center or contact our Support team at [email protected].