Keelway
Sign in Book a demo Get Keelway free
Carrier
M01Carrier TMS M02Invoice & Collections Agent M03Track & Trace M04Email Agent M05Voice Agent
Broker
M01Broker TMS M02Fraud AI · CarrierVet M03Track & Trace M04Email Agent M05Voice Agent
Integrations PricingSign in
Security & compliance

The security posture an enterprise broker procurement team expects.

Freight brokerages run on trust — with carriers, with shippers, and with the software that touches both. Keelway is built to clear the security review of a Fortune-1000 procurement team, not just a twelve-person SMB. This page is the public version of the security questionnaire we will fill out for you in detail under NDA.

SOC 2

Not certified — documentation in build-out

No attestation today, and we will not imply one. Trust Services Criteria scope we are building to: Security, Availability, Confidentiality. Readiness assessment shared under NDA. Attestation timing is a contract conversation, not a claim on a marketing page.
GDPR / CCPA

Article 28 DPA, service-provider terms

Standard Data Processing Agreement aligned with GDPR Article 28 obligations and CCPA service-provider terms. Available as an executable template or with mutual redlines. Subprocessor change notification with right-to-object on enterprise.
ISO 27001

Aligned, not yet certified

Internal controls modeled on ISO 27001 Annex A. Certification is on the post-SOC-2 roadmap; not currently in scope for audit. Customers who require an ISO-certified vendor should flag that at discovery.
HIPAA

BAA on request, scope-gated

Business Associate Agreement available where freight scope is healthcare-adjacent (hospital supply, clinical-trial logistics). Negotiated on a per-engagement basis with scope defined in the BAA itself.

Frequently asked questions

What is your SOC 2 status?+
Not certified. Keelway holds no SOC 2 attestation today and we are not going to imply otherwise. What exists is a security review and SOC 2 documentation program — the Trust Services Criteria scope we are building to (Security, Availability, Confidentiality) and our current readiness assessment, both shareable under NDA. Attestation dates and any commitments around them are negotiated in the enterprise contract, not published here.
Where is customer data stored?+
AWS us-east-1 by default for all customers. Enterprise customers can request a dedicated tenant in us-west-2 or ca-central-1 at no additional cost. EU data residency (eu-west-1, eu-central-1) is a roadmap item, not something you can buy today — ask and we will scope it against your contract. Data never leaves the chosen region outside of audited replication windows for disaster recovery.
How is data encrypted?+
In transit: TLS 1.2 or higher on every connection, with HSTS preload submitted and certificate pinning available for enterprise tenants. At rest: AES-256 on all customer data, including Postgres tables, S3 object stores, and Redis caches. Application-level field encryption for the most sensitive carrier-side identifiers (EIN, banking, SSN where collected for carrier setup).
What is your subprocessor list?+
Public subprocessors as of the current quarter: AWS (compute and storage), Cloudflare (edge and WAF), Resend (inbound carrier mail routing and outbound threaded replies), Google (Workspace SSO where a customer uses Workspace — Keelway holds no Gmail API access), Anthropic and OpenAI (LLM inference; no customer data used for model training under our enterprise terms), Stripe (billing only). Full list with data flows and processing purpose available under NDA on request. We provide 30 days' notice before any subprocessor addition, with a right-to-object for enterprise customers.
Do you train AI models on customer data?+
No. Customer carrier emails, rates, trust scores, and TMS data are never used to train shared foundation models or shared retrieval indexes. Every enterprise tenant runs against an isolated retrieval index scoped to its own data. Our LLM provider contracts explicitly opt out of training-data use.
What scopes do you request on Gmail?+
None in the default setup. Keelway issues a reply address instead of connecting to customer mailboxes, so Each brokerage is issued a Keelway-hosted reply address and publishes it as the contact on its load postings; carrier mail is delivered to that address and nowhere else. there is no OAuth consent screen and no standing read access to any customer inbox — which removes the largest single item from most security questionnaires. Customers who want Keelway reading a mailbox directly can opt into a read-only connection (Gmail, Microsoft 365, or IMAP) with scopes they approve on the provider's own consent screen and can revoke there at any time.
How do you handle security incidents?+
Security events page the founding team directly — Keelway is small enough that there is no tier-one queue to sit in. Enterprise customers are notified within 24 hours of any incident affecting their data, with a written preliminary report within 72 hours and a full post-mortem within 5 business days. Response-time SLAs are written into the enterprise contract rather than posted here, so what you get is what you signed. We do not run a public status page yet.
What about penetration testing?+
Independent third-party penetration test conducted annually by a CREST-certified firm. Most recent test summary available under NDA for prospective enterprise customers. We also run continuous automated vulnerability scanning on every deployed artifact and run a private bug bounty for select security researchers.
Do you sign DPAs and MSAs?+
Yes. Standard DPA template aligned with GDPR Article 28 obligations and CCPA service-provider terms, executable as-is or with mutual redlines. MSA template covers liability caps, indemnification, IP, and termination — built to clear most Fortune-1000 brokerage procurement reviews. BAA available where freight-data scope is healthcare-adjacent. Mutual NDA signed before any document exchange that requires it.
Security review on the agenda?

Send us your questionnaire. We'll send it back filled in.

Related