Security
CarrierBasis exists to produce records a brokerage may one day need to stand behind. That only works if the data underneath is protected and the records themselves can be trusted. This page describes how we approach both.
Certified infrastructure
CarrierBasis is hosted entirely on infrastructure whose providers hold SOC 2 Type 2 attestations and ISO 27001 certifications — covering our application hosting, database, file storage, and AI processing. To be precise about what that claim means: those certifications belong to our infrastructure providers and cover the platforms the Service runs on; NewWay Digital does not itself hold these certifications. We select providers on this basis deliberately, and we're glad to identify our current providers and their certifications to customers on request.
Encryption
- All traffic to and within the Service is encrypted in transit using TLS.
- Customer data is encrypted at rest by our hosting and storage providers.
- Credentials customers supply for their own systems (such as TMS connections) are stored encrypted with a dedicated application-level key, separate from general database encryption.
Tenant isolation
CarrierBasis is multi-tenant, and isolation is enforced at the database layer: every tenant-owned record is protected by row-level security policies keyed to the authenticated tenant, so one brokerage's data is not reachable from another's session — including by our own background processing, which operates under the same tenant-scoped controls as an ordinary request.
Who did what: authenticated identity
Users sign in with individual accounts. Actions that matter — resolving a finding, recording the basis for a decision, approving, sealing — are attributed to the authenticated user who performed them, and administrative changes to a brokerage's policy settings are restricted to that brokerage's administrators.
Record integrity
Data practices
- Brokerage and carrier data is never sold. See our Privacy Policy.
- Customer content is used to provide the Service to the customer it belongs to — not for advertising.
- Carriers referenced by sealed records are never deleted from underlying storage in a way that would orphan the evidence; removal from view is presentational.
Reporting a vulnerability
If you believe you've found a security issue in the Site or Service, please email contact@workanewway.com with "Security report" in the subject. We appreciate good-faith reports and will respond promptly. Please don't access data that isn't yours or disrupt the Service while investigating.
Questions
Security questionnaires and customer-specific questions: contact@workanewway.com.