Skip to main content
Security

Security for operational supply-chain data.

LaneGuard is built for supply-chain teams under review — AES-256 encryption at rest, TLS 1.3 in transit, role-based access, retained audit history, and SOC 2 Type II attested in October 2025.

Secure global supply chain network
Security pillars

Built for the way operations work.

Data protection

AES-256 at rest. TLS 1.3 in transit. Operational logs retained 1 year; audit logs retained 7 years.

Role-based access

Admin, Manager, Analyst, and Viewer — each scoped to the surfaces that role needs.

Audit history

Every write is recorded. Risk-score overrides require a reason code and are logged.

Secure integrations

Read-only scopes where possible. SAP S/4HANA via OData; Project44 / FourKites via API connector.

Human review for AI

All High and Critical alerts require human sign-off before any action is taken.

Enterprise authentication

SAML 2.0 / Okta integration supported for SSO on Enterprise Network.

Compliance posture

Aligned to the standards your auditors expect.

SOC 2 Type II

Attested October 2025 — Security, Availability, and Confidentiality for the LaneGuard production environment.

ISO 27001

Pending. Final audit scheduled for Q3 2026. Not yet certified.

Encryption

AES-256 at rest and TLS 1.3 in transit.

Retention

Operational logs 1 year. Audit logs 7 years for compliance.

Security & compliance

Attested controls, stated plainly.

ISO 27001 is not yet certified — the final audit is scheduled for Q3 2026. We publish only what has been attested.

SOC 2 Type IIAttested October 2025
SOC 2 scopeSecurity, Availability, Confidentiality — Production Environment
ISO 27001Pending — final audit scheduled Q3 2026
EncryptionAES-256 at rest · TLS 1.3 in transit
Operational logsRetained 1 year
Audit logsRetained 7 years for compliance
RBAC rolesAdmin · Manager · Analyst · Viewer
AuthenticationSAML 2.0 / Okta integration supported
LaneGuard automates
  • Risk scoring
  • Signal aggregation
  • Notification triggering
Humans decide
  • Supplier switching
  • Purchase-order cancellation
  • Rerouting approval
Overrides

Users may manually override any risk score. Every override is logged with a required reason code, and 88% of assessments pass through manual review — all High and Critical alerts require human sign-off.

Integrations

Connected to the systems your lanes already run on.

These are technical integrations, not formal partnerships or endorsements. Each connector runs on the narrowest permission scope that supports the workflow.

SAP S/4HANA
Integration · Live direct OData API
Data inPurchase Orders, Bill of Lading, Supplier Master Data
Data outRisk score updates tagged to PO numbers
Permission scopeRead-only — Logistics / Procurement modules
FallbackSecure daily SFTP CSV upload
Project44 / FourKites
Integration · API connector
Data inReal-time GPS coordinates and ETA updates
Data outNone
Permission scopeShipment-level tracking access
FallbackManual milestone entry
Security review

Run a security review with our team.

Architecture diagrams, sub-processor list, and security questionnaire on request.