DockOptima Back to home

Security & Compliance

DockOptima handles live operational data for warehouses, carriers and drivers. This page summarises how that data is protected, where it lives, and what we can provide during a procurement or vendor security review.

Tenant isolation

Every record is scoped to a single organisation and enforced in the database itself with row-level security. One customer cannot query another customer's appointments, trailers or documents — even in the event of an application bug.

Encryption

TLS 1.3 for all data in transit and AES-256 encryption at rest, including database storage, backups and uploaded delivery documents.

UK / EU hosting

Application, database, authentication and file storage run in UK/EEA regions. We do not transfer personal data outside the UK/EEA.

Certified infrastructure

DockOptima runs on cloud infrastructure that is independently audited and certified to ISO/IEC 27001:2022, SOC 1 and SOC 2 Type II. Certificates and reports are available from our infrastructure provider on request.

Access control & audit

Granular role-based access (Owner, Admin, Operator, Gate Attendant, Yard Driver, Spectator), enforced server-side. Facility, dock, appointment and gate changes are written to an immutable audit trail. SAML 2.0 single sign-on is available for enterprise accounts.

Payments

Card data is handled entirely by Stripe (PCI-DSS Level 1). DockOptima never sees, stores or processes card numbers.

Our compliance position

DockOptima does not currently hold its own ISO/IEC 27001 certificate. We inherit the certified controls of our hosting and payment providers — ISO/IEC 27001:2022, SOC 1 and SOC 2 Type II for infrastructure, PCI-DSS Level 1 for payments — and apply application-level controls on top of them, as described above. We state this plainly so that your security team can assess us accurately.

Data protection

  • DockOptima acts as Data Processor; your organisation is the Data Controller.
  • A GDPR Article 28 Data Processing Agreement is available to every customer.
  • Named sub-processor list provided on request; customers are notified of material changes.
  • Customer data is deleted or returned on termination, within 30 days of request.
  • Customer operational data is never used to train AI models.
  • Signed-in users can export their stored data at any time from Settings.

Availability & resilience

The platform is served through a global edge network with automated daily encrypted backups of the production database, retained on a rolling basis and restorable to a point in time.

Reporting a vulnerability

If you believe you have found a security issue, email contact@dockoptima.com with the details. We aim to acknowledge reports within two working days. Please do not publicly disclose an issue before we have had a chance to respond.

Need documentation for procurement?

Read our Data Processing Agreement or request a signed copy and security questionnaire.

This page describes our current practices in good faith and is not legal advice.