SOC2C

Is this your company? Buyers are checking ShipFusion Inc here. Claim shipfusion.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
ShipFusion Inc logo

ShipFusion Inc

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

ShipFusion Inc is SOC 2 compliant.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

Shipfusion is a Third Party Logistics (3PL) company that combines flexible, reliable fulfillment with powerful, real-time in-house technology, operating facilities across North America. As we develop our own platforms and have integrations with leading marketplaces, carriers and other Ecommerce partners, data security, privacy and compliance are critical to our success. These compliance controls are not just checkmarks to feel better, but rather represent a serious commitment to best-practise technology development and operations across the board. By integrating many of these approaches into e

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

1

Subprocessors

7
  • W
    Wiz · Security
  • V
    Vanta · Security
  • A
    Amazon Web Services · Cloud provider
  • B
    Bitbucket · Version control
    United States
  • G
    Google Workspace · Identity provider & Office Productivity Software
    United States
  • S
    Slack · Collaboration
    United States
  • A
    Addigy · IT Device & Remote management
    United States

Compliance leadership

The person who leads ShipFusion Inc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. ShipFusion Inc's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is ShipFusion Inc SOC 2 compliant?
ShipFusion Inc is SOC 2 compliant. On SOC2C this listing is Listed.
Can I use ShipFusion Inc's SOC 2 for a vendor risk assessment?
Yes. ShipFusion Inc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is ShipFusion Inc penetration tested?
ShipFusion Inc hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is ShipFusion Inc secure?
Security isn't a single yes/no, but ShipFusion Inc is SOC 2 compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does ShipFusion Inc have a bug bounty or vulnerability disclosure program?
ShipFusion Inc hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@shipfusion.com or via a /security page (ShipFusion Inc lists a security contact).

Answers published by ShipFusion Inc

Reproduced from ShipFusion Inc's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Have you worked with HIPAA-compliant clients and how do you comply as a business partner?
Yes, we have HIPAA-compliant clients and our role as a 3PL means we fall into the HIPAA Business Associate role. Our approach is that we sign a Business Associate agreement that commits us to ensuring we respect your compliance requirements, and our internal compliance controls (visible in this trust center) are designed to cover the requirements of HIPAA Business Associates, together with various other data privacy frameworks, such as those included in SOC2, GDPR and Californian CCPA.
How do you handle the customer Personally-Identifiable Information (PII) we send in shipment requests?
Personally-Identifiable Information (PII) is clearly identified in our data policies and their storage is limited across the system. In summary, we have little use for your customer PII beyond generating the necessary shipping labels and documents, hence our retention and systems that handle PII are limited and tightly controlled. We also have regular audits from Ecommerce partners like Amazon, who require stringent adherence to their Customer PII data policies for us to maintain integrations with them, irrespective of our clients' requirements. We also operate in states like California and ship to European destinations, so all PII data has to also comply with CCPA and GDPR frameworks. Customer PII also can be from HIPAA-compliant clients, so we treat this data equally across our systems to for simplicity and security. We are pursuing 3rd party certifications such as SOC2 and using platforms like Vanta that power this trust site to provide external confidence and verification that we are adhering to these statements.
How do you monitor for security breaches?
We use Wiz.io (https://www.wiz.io/), the industry-leading cybersecurity platform, to continuously scan logs, configuration of our server and hosting infrastructure, and code of our software. This provides us with real-time alerts on suspicious behaviour across our entire environment, such as a potential security breaches or any misconfigurations that may lead to a weakened security posture. We also have other monitoring tools such as Datadog that allows us to detect real-time changes where breaches might not be easily discoverable, such as unusual network behavior, external bad hosts attempting to request URLs or server utilizations that are abnormal. We run malware scanners that also report any detected malware or unexpected applications across both our server environment and corporate IT hardware. All of this is centralized into alerts and investigated as they are suspected.
Where are your servers located?
Our datacenter presence is all located within Amazon AWS data centers in the United States. No data is processed or stored in other countries or territories, and all data is encrypted in transit to and from our services, and at rest inside our services
What do you base your policy framework on?
We first started with CIS Critical Security Controls v8, as we felt that this provided a software-orientated security-first foundation for our policy framework. We also noted that there would be a fair amount of overlap with SOC2 controls, giving us an efficiency of satisfying a higher-level of software security with a standardized audit certification that is easily recognized. Once we have obtained our SOC2 Type II certificate, we'll be exploring further enhancements from the CIS control suite, ISO 27001 specification and recommendations from our 3rd parties and partners.

Business & Industrial peers that completed SOC 2