Skip to main content
LogisticsAI

Security · document handling

The question your team must answer

Before you upload a transport document, know where it goes.

See how a permit moves through private storage, bounded AI processing, organisation-scoped review and a human-approved result — and which choices still need your agreement.

01

The short answer

Files, records and review actions are kept inside explicit access and decision boundaries.

Private file storage

Implemented

How it is enforced

Permit source files and exports use non-public storage buckets with organization-aware object policies.

Organization-scoped records

Implemented

How it is enforced

Permit tables use organization membership policies to restrict record access.

Source-linked extraction

Implemented

How it is enforced

Extracted fields can retain page, snippet, confidence and review information where available.

Deletion controls

Implemented

How it is enforced

Workspace administrators can delete a permit; source files, exports and extracted payloads are purged, with failed storage cleanup retried by the worker.

02

One document. Every boundary made visible.

Follow the current permit workflow from upload to reviewed result. OpenAI appears exactly where the document crosses an external processing boundary.

  1. 01

    Upload

    A PDF or supported image is placed in private permit storage under its organization and document path.

    Implemented
  2. 02

    Provider processing

    The complete PDF or image is sent to the configured OpenAI Responses API model for extraction.

    Implemented
  3. 03

    Structured result

    The returned JSON is schema-checked, validated and stored with the organization-scoped permit record.

    Implemented
  4. 04

    Human review

    A user reviews sources, uncertainty and corrections before approving an export.

    Implemented

03 · indexed trust dossier

Start with the answer. Open the evidence when you need it.

Each section separates the control visible in the current product from its operational boundary. This is the detail an IT, privacy or procurement review can inspect.

01Identity and organisation accessOpen detail

Authenticated access

Application accounts and sessions are handled through Supabase Auth.

Organization-scoped records

Permit tables use organization membership policies to restrict record access.

02File and record isolationOpen detail

Private file storage

Permit source files and exports use non-public storage buckets with organization-aware object policies.

Separate permit domain

Permit documents, extraction jobs, review events and exports are separate from emissions records.

03AI processing boundaryOpen detail

Upload

A PDF or supported image is placed in private permit storage under its organization and document path.

Provider processing

The complete PDF or image is sent to the configured OpenAI Responses API model for extraction.

Structured result

The returned JSON is schema-checked, validated and stored with the organization-scoped permit record.

OpenAI request storage

Permit requests are sent with the OpenAI API parameter store: false. This prevents application-requested response storage, but does not by itself define every provider-side abuse-monitoring or retention condition.

Model training

LogisticsAI does not use customer permits to train a model of its own. Applicable OpenAI data-use terms and account controls must be confirmed for the production agreement.

04Human review and traceabilityOpen detail

Source-linked extraction

Extracted fields can retain page, snippet, confidence and review information where available.

Human review

A user reviews sources, uncertainty and corrections before approving an export.

05Deletion and retentionOpen detail

Source documents

Workspace administrators can explicitly delete a permit. Its private source file and generated exports are then purged.

Structured records

Deletion removes extracted fields and provider payloads. A content-free tombstone and sanitized audit timeline remain as a deletion record.

Provider and infrastructure data

Backups, security logs and provider-side records can follow separate operational or contractual schedules.

Deletion verification

Failed private-storage cleanup is kept inaccessible and retried by the background worker. Backups remain subject to infrastructure schedules.

Current assurance and certification status
  • No SOC 2 or ISO 27001 certification is claimed.
  • No universal EU-only processing or storage claim is made.
  • No zero-retention or zero-risk promise is made.

Next · your requirements

Bring your security checklist before implementation.

We can map each question to the workflow, data path, provider and responsibility that it affects. A meeting is optional.