Security and data handling

Your shipment documents carry your clients’ commercial details. Here is exactly what happens to them.

Where documents go

Uploaded files are stored outside the public web folder, under random file names, and are only served to signed-in members of your workspace.

To draft a shipment, the documents are sent over an encrypted connection to Anthropic’s Claude API. Anthropic does not train its models on data sent through its commercial API. The answer comes back to Tariffly and is stored in your workspace.

Who can see what

Every workspace is separate. Members only see their own workspace’s shipments. Owners manage the team, reviewers approve drafts, and operators prepare them.

Keeping a record

Every upload, AI draft, edit, comment, approval and export is logged with the person and the time. You can see the log on each shipment.

Your data, your call

Owners can delete any shipment and its files, export the whole workspace as JSON, or delete the workspace and every document in it from the Settings page.

  • Encrypted in transitHTTPS everywhere, including the connection to the AI provider.
  • Passwords hashedNever stored in plain text. Logins are rate-limited.
  • Forms protectedEvery action that changes data checks a per-session token.
  • Strict browser rulesA content security policy blocks scripts from anywhere but Tariffly.
  • No model trainingYour documents are never used to train AI models.
  • A human decidesNothing is approved without a reviewer from your team.

Questions about security or a supplier questionnaire to fill in? Send it to us.