Security & Compliance
Trade documents contain sensitive commercial data. We treat them accordingly.
Declared values, consignee DUNS, HS codes, shipper relationships, freight charges — your trade documents contain data that competitors, duty evaders, and counterfeit supply chain actors would find valuable. Tradevynt is built with controls appropriate to that sensitivity, and we are transparent about where we are on the compliance roadmap.
Data Handling
Three layers of protection
TLS 1.3 for all API calls, webhook deliveries, and web interface traffic. TLS 1.2 and below are not accepted. Certificate pinning is available for enterprise API clients on request.
AES-256 encryption for all document storage. Documents are deleted within 90 days of processing completion unless you request earlier deletion. Extracted field data is retained per your plan's data retention period. No retention beyond your subscription unless legally required.
Role-based access control with audit logging for all document access events. No Tradevynt employee can access document content without a customer-initiated support request and documented justification. Access logs are retained 12 months and available for your review on request. Built with SOC 2 Type II controls in mind — compliance roadmap active for 2026.
Data Residency
Your documents stay where you need them.
Processing occurs in the same region as storage. Your document data does not travel across borders without your explicit consent.
Tradevynt prepares entry data. Your licensed customs broker files it.
Tradevynt extracts, validates, and transmits the prepared customs entry data to your broker's system. We are not a licensed customs broker or filing agent. Official AMS and ACE filing with US Customs and Border Protection is handled by your licensed customs broker. This distinction matters: we prepare the complete, validated entry packet; your broker is the licensed professional who submits it to CBP and bears the legal filing responsibility.