Security & trust

Designed toward enterprise security and audit readiness.

Freight Passport treats cargo authorization as a server-side, tenant-scoped decision with current evidence, least privilege, controlled exceptions, and durable history.

Capability map

How this part of Freight Passport is structured.

Explore the interactive demo →
01

Identity and authorization

Tenant isolation, object/function authorization, scoped roles, and recent strong authentication protect sensitive actions.

  • Phishing-resistant MFA path
  • Facility and carrier scope
  • Separation of duties
02

Release credentials

Credentials are signed, short-lived, one-use, state-bound, and redeemed against current server authority.

  • Atomic redemption
  • No bearer values in URLs or logs
  • Persisted replay signal
03

Evidence and privacy

The architecture emphasizes provenance, freshness, private storage, data minimization, consent/retention boundaries, and legal hold design.

  • No raw biometric templates stored in Freight Passport architecture
  • Minimum necessary disclosure
  • Environment separation
04

Operational resilience

Controlled overrides, Emergency Operations Mode design, bounded workers, monitoring contracts, and fail-closed behavior define exceptional paths.

  • Append-only or tamper-evident custody events
  • Secure development lifecycle
  • Explicit outage boundaries

Production operations, alerts, backup/restore drills, external assessment, and legal approval remain pilot gates.

See it in context

Test the handoff decision yourself.

Use fictional shipment data to explore a valid arrival, a blocked mismatch, a protected change, and a replay attempt.