Security

Regulated data, handled the way regulated data should be.

Shipment vitals, batch records, and license data carry real compliance weight. Here's what we store, how long we keep it, who can see it, and how it's protected - stated as it stands today, without overclaiming.

Data handling

What we hold, and for how long.

What's stored

Shipment vitals, batch records, license validity dates, order and dispatch history, and the network structure you configure. Sensor readings are stored as time-series against the shipment they belong to.

Retention

Operational records are retained for as long as your account is active and for the period your compliance obligations require afterwards. Retention windows are set with you at onboarding rather than assumed.

Access scope

Access is scoped to the network you operate. A distributor sees their own compliance and stock; a manufacturer sees the tiers below them. No party sees data outside their place in the chain.

Controls

How it's protected.

Encryption in transit and at rest

Data moving between your devices and Canfrox is encrypted in transit, and stored data is encrypted at rest. Credentials are never stored in plain text.

Role-based access

Manufacturer, distributor, and stockist roles each see a view matched to their position - so temperature, expiry, and license data reaches the people responsible for it and no one else.

Separation by network

Each network's data is logically separated. One customer's shipment vitals and compliance records are never visible to another.

Our compliance posture, honestly

We state our security posture as it currently stands, not as a wish-list. Where a formal certification is in progress, we'll say so plainly and share status on request rather than implying it already exists. If a control matters to your compliance team, raise it during onboarding and we'll give you a straight answer on where it stands.

Vitals, on your real shipments

Bring your security questions to onboarding.

Book a walkthrough and we'll go through data handling, access, and retention against your own compliance requirements.