Security
Security at Enreship
Last updated: September 17, 2026
1. Implemented application safeguards
Enreship's application requires authenticated access and applies role-based authorization to protected functions. Connected marketplace authorization uses platform OAuth flows where supported. Service configuration uses HTTPS endpoints, AWS S3 object storage, database connection pooling, and application error monitoring.
Sensitive integration credentials are held in server-side configuration rather than exposed in the public website. Access to seller and shipping information is intended to be limited to the workflow and personnel that require it.
2. Shipping data
Shipping information may include recipient name, delivery address, phone number when provided, order and shipment identifiers, parcel details, labels, and tracking events. It is used for order and delivery operations, not for advertising or buyer profiling.
For the planned Amazon integration, Amazon Restricted PII is limited and deleted as described in the Privacy Policy and planned SP-API data handling page.
3. Monitoring and issue tracking
The application is configured with Sentry for error monitoring and Jira for support issue tracking. Sentry default PII and request-body collection are disabled. Before-send filters remove user records, cookies, query strings, request and response bodies, unsafe headers, application extras, breadcrumb content, exception messages, tags, and transaction names before transmission. Structured Sentry logs and performance transactions are disabled.
Enreship uses Planck Proof for regular agentic API penetration testing of authorized Enreship API assets. Findings are reviewed and tracked for remediation. This does not represent a certification or a fixed monthly or annual testing cadence.
We do not publish unverified claims about vulnerability-scan frequency, log-review cadence, log-retention periods, incident-plan review cadence, or remediation SLAs.
4. Claims not made
This page does not represent that Enreship has a certification, independent assessment, Amazon approval, or specific infrastructure/control deployment that is not documented in the available implementation evidence. Detailed controls may be provided under appropriate confidentiality terms after verification.
5. Report a security issue
Please report suspected vulnerabilities, unauthorized access, or privacy incidents to info@enreship.com. Include enough detail to reproduce or investigate the issue, but do not send passwords, access tokens, or customer PII by email.