Security & Compliance
DockOptima handles live operational data for warehouses, carriers and drivers. This page summarises how that data is protected, where it lives, and what we can provide during a procurement or vendor security review.
Tenant isolation
Every record is scoped to a single organisation and enforced in the database itself with row-level security. One customer cannot query another customer's appointments, trailers or documents — even in the event of an application bug.
Encryption
TLS 1.3 for all data in transit and AES-256 encryption at rest, including database storage, backups and uploaded delivery documents.
UK / EU hosting
Application, database, authentication and file storage run in UK/EEA regions. We do not transfer personal data outside the UK/EEA.
Certified infrastructure
DockOptima runs on cloud infrastructure that is independently audited and certified to ISO/IEC 27001:2022, SOC 1 and SOC 2 Type II. Certificates and reports are available from our infrastructure provider on request.
Access control & audit
Granular role-based access (Owner, Admin, Operator, Gate Attendant, Yard Driver, Spectator), enforced server-side. Facility, dock, appointment and gate changes are written to an immutable audit trail. SAML 2.0 single sign-on is available for enterprise accounts.
Payments
Card data is handled entirely by Stripe (PCI-DSS Level 1). DockOptima never sees, stores or processes card numbers.
Our compliance position
DockOptima does not currently hold its own ISO/IEC 27001 certificate. We inherit the certified controls of our hosting and payment providers — ISO/IEC 27001:2022, SOC 1 and SOC 2 Type II for infrastructure, PCI-DSS Level 1 for payments — and apply application-level controls on top of them, as described above. We state this plainly so that your security team can assess us accurately.
Data protection
- DockOptima acts as Data Processor; your organisation is the Data Controller.
- A GDPR Article 28 Data Processing Agreement is available to every customer.
- Named sub-processor list provided on request; customers are notified of material changes.
- Customer data is deleted or returned on termination, within 30 days of request.
- Customer operational data is never used to train AI models.
- Signed-in users can export their stored data at any time from Settings.
Availability & resilience
The platform is served through a global edge network with automated daily encrypted backups of the production database, retained on a rolling basis and restorable to a point in time.
Reporting a vulnerability
If you believe you have found a security issue, email contact@dockoptima.com with the details. We aim to acknowledge reports within two working days. Please do not publicly disclose an issue before we have had a chance to respond.
Need documentation for procurement?
Read our Data Processing Agreement or request a signed copy and security questionnaire.
This page describes our current practices in good faith and is not legal advice.