OPERANTA
Trust · Data Security

Data security built for logistics clients.

Practical, auditable controls that keep freight forwarding, NVOCC, 3PL and customs data safe — inside our delivery centres, on our endpoints and across our processes.

Our security posture

OperantaOps operates from controlled-access delivery centres with layered administrative, technical and physical controls aligned to ISO 27001. We are a service provider that accesses your systems to deliver operations — we do not host your shipment or financial data. Every specialist logs into your TMS, ERP, CRM or customer portals using access you provision under your own user licences and permissions.

Access & identity

  • MFA enforced on every corporate and client system account
  • Least-privilege access with role-based provisioning
  • Quarterly access reviews and immediate deprovisioning on offboarding
  • Single sign-on where the client provides an SSO instance
  • Password rotation and complexity policies enforced technically

Endpoints & network

  • Company-managed endpoints only — no personal devices
  • Full-disk encryption on every workstation
  • Endpoint detection and response (EDR) on all machines
  • Restricted internet, controlled outbound egress and no removable media
  • Web filtering and secure DNS on all corporate networks

People & process

  • Individual and entity-level NDAs signed at onboarding
  • Background verification for every specialist
  • Documented SOPs, four-eyes review and independent QC audits
  • Annual security awareness training with phishing simulations
  • Documented incident response with client-notification SLAs

Data processing & GDPR

OperantaOps acts as a data processor (or Singapore data intermediary / UK GDPR processor) under our clients' instructions. We sign a Data Processing Agreement (DPA) with every client and back cross-border transfers using EU Standard Contractual Clauses where required. We honour data-subject rights, sub-processor transparency and audit rights as set out in the DPA.

Delivery centre security

  • Card-access-controlled floors with visitor logs
  • CCTV coverage of production and access areas
  • Physical separation of client engagement zones where required
  • Print / paper restrictions on production floors
  • Business continuity and backup facilities for critical desks

Frequently asked questions

Are you ISO 27001 certified?

Our controls are aligned to ISO 27001. We do not currently claim a live ISO 27001 certificate. We are transparent about this and will not misrepresent our certification posture.

Where is our data hosted?

Inside your systems. OperantaOps does not host your shipment or financial data. Our specialists log into your TMS, ERP and portals using accounts you provision and control.

Do you sign a DPA?

Yes. We sign a Data Processing Agreement with every client and back cross-border processing with EU Standard Contractual Clauses where required.

How do you handle an incident?

We follow a documented incident response playbook with defined client-notification SLAs, root-cause analysis and remediation reporting.

Can we audit your controls?

Yes. Client audit rights are set out in the DPA and are exercised on notice under a mutually agreed scope.

Talk to us about your security requirements.

We are happy to walk your InfoSec team through our controls and share our DPA template on request.