AfterShip vs Narvar vs Malomo: What an Enterprise Buyer Can Actually Verify

Updated: August 24, 2026

·

21 mins read

Three vendors, one buying committee, and three very different amounts of public evidence. That is the honest starting condition for anyone comparing AfterShip vs Narvar vs Malomo at 50,000 orders a month and up, and it is the part no feature matrix shows you.

Your engineering lead wants to read the API surface. Your security reviewer wants attestations and incident history. Your CFO wants a number before anyone books a call. Whether those three people can do their jobs depends entirely on what each vendor has chosen to publish, and the three vendors on this shortlist have chosen very differently.

The hidden tax on an enterprise post-purchase contract is not on the invoice. It is in everything you cannot check before you sign.

One correction before any scoring. Malomo is Redo's Shopify-native tracking product; Redo announced the acquisition in February 2026. The acquisition banner is still live on Malomo's own pricing page, read 24 August 2026, and the announcement it links to is dated February 2026. That single fact reshapes this shortlist more than any capability comparison will, for reasons the platform section takes up.

Six criteria decide this evaluation, and every one of them is checkable from outside a sales call: public API documentation, whether open or gated; certifications and status transparency; platform support beyond Shopify; published price transparency; the documented path to get your data back out; and carrier scope, with its published count and the scope of that count stated. What follows scores all five vendors in the landscape, criterion by criterion, in that order.

Scored that way, two vendors publish evidence against all six: AfterShip and Redo. That is not what this shortlist prepares you for, and Redo is credited for it below.

Where they separate is depth. AfterShip is the only vendor here that names both SOC 2 Type II and ISO 27001; parcelLab names the first and not the second, and Redo names SOC 2 without a type.

AfterShip is also the only one publishing an SLA document with service credits and a response matrix, where Metapack publishes an availability figure. A security review needs a named report type, a named standard and a written agreement with remedies attached, and one vendor here publishes all three.

What an enterprise post-purchase evaluation actually has to prove

A post-purchase decision at this volume is never one person's call. It clears three reviewers, and each one is looking for a different artefact.

  • Engineering wants the integration surface and the exit. Can they read the endpoint reference, the rate limits and the retry semantics without an account? Is there a documented way to get the order and tracking history back out?
  • Security wants attestations, incident history and a data-processing position. Which frameworks are named, by which report type, and is there a status page with enough history to show how the vendor behaves in a bad week?
  • Finance wants to size the thing. Is there a published price at a volume resembling yours, or does every number start with a discovery call?

None of that is a feature question, which is why feature comparisons keep failing this reader. A vendor can hold SOC 2 Type II, run a rigorous penetration-testing programme and staff a serious platform team, and still leave your security reviewer with nothing to read on a Tuesday afternoon. Those are two different facts about the same company.

Enterprise buyers should score post-purchase vendors on published evidence, not vendor claims.

That is also the only version of this comparison that survives contact with a procurement process. Claims get repeated in a deck. Published evidence gets forwarded to a reviewer, and it either holds up or it does not.

The integration surface: what each vendor lets you read before you sign

Start with the artefact your engineering lead will ask for first, because it is the one that separates these vendors most cleanly: the developer documentation, and whether it opens without a login.

On Narvar, it does not. developer.narvar.com redirects to Narvar's own single sign-on, read 21 August 2026, so there is nothing for a reviewer to evaluate before a commercial relationship exists. That is a statement about access, not about capability. Narvar's documentation is gated rather than missing, and the distinction matters: a committee that signs will get it, and a committee that is still deciding will not.

Redo, which is where Malomo's tracking now lives, is the second most readable vendor in this set, and by a wider margin than the shortlist implies. It publishes an open, unified and versioned API. It publishes a per-order price for tracking. It publishes a security policy naming SOC 2, linked from its own site footer, alongside a live Trust Center, and the Malomo side runs a per-component status page with 90-day uptime.

Redo's security policy page names SOC 2 without a type, and neither an ISO 27001 certification nor a service-level agreement appears on it. Your security reviewer can tell the difference between a report type named and a report type left open, and your procurement lead can tell the difference between an uptime page and an uptime commitment.

Metapack, now one of five modules inside ShipStation Global, sits in the middle: its catalogues are open, while the full developer centre is gated behind an approval step. parcelLab publishes openly on GitBook, including an explicit webhook retry policy.

Where a vendor sits on that spectrum sets the pace of your evaluation. Gated documentation means the technical review cannot begin until a commercial conversation has, which pushes the engineering assessment behind the demo, the NDA and the security questionnaire. Open documentation lets the two run in parallel, and at renewal season that is weeks, not days.

AfterShip publishes open API documentation, rate limits and an enterprise SLA, no sales call.

In practice that means your engineering lead can answer four questions this afternoon. Rate limits are published per endpoint rather than described in general terms, and the documented 429 responses and X-RateLimit headers are there on the page, so a client can be built to back off correctly instead of guessing. Go and read the numbers yourself in AfterShip's developer documentation. That you can is the entire point.

Retry behaviour is specified rather than implied: webhooks retry "up to 14 times with exponential backoff", on a stated formula of 2 to the power of the retry count, multiplied by 30 seconds. Versioning is date-based with a public changelog, so an integration team can see what changed and when.

The published SDKs, the CSV export and the upload path all sit on that same open surface. For a replatforming team, that is the difference between planning a migration and requesting a scoping call to find out whether one is possible.

Carrier scope is the one criterion where the number itself is the answer. AfterShip publishes 1,400+ carrier integrations for Tracking on its Tracking product page, and states on the same page that it adds up to 50 new carriers a month as a member of the UPU Consultative Committee. That figure is Tracking scope, and it is worth reading it as exactly that rather than as a blended platform total.

Read the six criteria as a single grid and the pattern is hard to unsee: the amount a vendor publishes is itself a procurement signal.

CriterionNarvarMalomo (Redo)MetapackparcelLabAfterShip
Public API documentationGated, redirects to sign-on (21 Aug)Published, opens with no login (24 Aug)Partial: catalogues published, developer centre gated (21 Aug)Published, opens with no login (24 Aug)Published, opens with no login (21 Aug)
Certifications and status transparencyCertifications not published; Status published (21 Aug)Certifications published, report type not named, ISO 27001 not named; Status published (24 Aug)Not established in this passCertifications published, report type named, ISO 27001 not named; Status published (21 Aug)Certifications published, report type named, ISO 27001 named; Status published (21 Aug)
Platform support beyond ShopifyPublished (21 Aug)Published, Shopify commerce backend required (24 Aug)Published, API-first (21 Aug)Published, platforms named (24 Aug)Published, platforms named (21 Aug)
Published price transparencyNot published (21 Aug)Published, on two surfaces that disagree (24 Aug)Not published, pricing URL redirects (21 Aug)Not published, pricing URL returns 404 (21 Aug)Published to a stated volume (21 Aug)
Data export and migration pathNot readable, documentation gated (21 Aug)Published (24 Aug)Not established in this passPublished (24 Aug)Published (21 Aug)
Carrier scopePublished with count (21 Aug)Published, enumerated without a count (24 Aug)Published, inconsistent across own surfaces (21 Aug)Published, no count stated (24 Aug)Published with count and scope stated (21 Aug)

What each vendor's own surfaces published, every one read in August 2026.

Security and reliability evidence

Your security reviewer has a narrower job than the rest of the committee. They are not assessing whether a vendor is secure. They are assessing whether the vendor has given them enough to write a recommendation, and the two questions have very different answers across this set.

AfterShip's trust centre is linked from the site footer and names what a reviewer needs to open a file: SOC 2 Type II, ISO 27001, GDPR, CIS Benchmarks, annual third-party penetration testing, a HackerOne programme, a subprocessor list and a data processing agreement. Single sign-on sits in the enterprise tier alongside it.

parcelLab publishes a serious set of its own, and it deserves stating precisely: SOC 2 Type II, HIPAA, GDPR and CCPA, an ePrivacy Seal, Vanta monitoring, annual penetration testing, and ISO 42001. Read that last one carefully, because it is easy to skim as a sibling of ISO 27001 and it is not. ISO 42001 is an AI management standard. parcelLab does not publish ISO 27001.

Two of those items do work the others cannot. A subprocessor list tells your reviewer which third parties touch order data before they have to ask, and a published data processing agreement gives your legal team something to redline while the technical evaluation is still running.

Narvar publishes no openly accessible certification evidence, which is the same access story its documentation tells. Redo's security policy page, credited above, is the second most substantive surface in the set.

Status pages are the one criterion where this set converges. AfterShip publishes per-component status, Narvar publishes 90-day per-component uptime, Malomo runs a per-component page with 90-day uptime at status.gomalomo.com, and parcelLab publishes five years of incident history. Metapack's status-page history was not established in this pass.

All four are real evidence, and none of them separates these vendors. The separation is in the SLA, and it is the strongest cell in this comparison.

aftership.com/enterprise-sla, dated 11 April 2025, commits in writing that AfterShip "shall use reasonable endeavours to achieve a 99.9% Service Uptime during any given calendar month". That qualifier is real and should be read as written.

What makes the page matter is the machinery attached to that number. Service credits are available. Scheduled maintenance carries 30 days of notice. Incidents run against a published response matrix from P1 to P4, and a P1 carries a first reply within two hours and a resolution target of six hours.

That matrix is the part your engineering lead will care about most, because it is the difference between a vendor promising to take an outage seriously and a vendor writing down what taking it seriously means.

Metapack publishes a contracted 99.99% availability figure on its developer site, which is a higher number on a page. Narvar, Redo and parcelLab publish no availability commitment a buyer can read at all. AfterShip publishes an agreement: a named uptime target, a remedy when it is missed, a notice period, and response times your team can hold someone to at two in the morning during peak.

VendorCertifications, as namedAvailability commitmentPublished priceRetention and exportCarrier scope
NarvarNone published (21 Aug)None published (21 Aug)-Privacy-policy retention section, no period stated (24 Aug)"Integrated with 1,000+ carriers", own site (21 Aug)
Malomo (Redo)SOC 2, report type not stated; GDPR and CCPA; TLS in transit, AES-256 at rest; annual independent penetration test (24 Aug)None published (24 Aug)"Order tracking $0.08 per tracked order", per tracked order, redo.com/pricing (24 Aug)Privacy-policy retention section dated 26 Feb 2026, no period stated; scheduled CSV delivery to read-only SFTP (24 Aug)66 carriers enumerated in the API docs, 17 requiring extra credentials; no count published (24 Aug)
Metapack-"Contracted 99.99% availability", developer site: a figure, with no credits and no response matrix (21 Aug)-Tracking capped at 90 days (21 Aug)Not printed: own surfaces publish conflicting counts (21 Aug)
parcelLabSOC 2 Type II; HIPAA, GDPR, CCPA; ePrivacy Seal; Vanta monitoring; annual penetration testing; ISO 42001, an AI management standard. ISO 27001 not named (21 Aug)None published (21 Aug)-Privacy-policy retention section, no period stated; raw tracking and communication data exports via the parcelLab App; RMA exports by webhook, API or flat file to SFTP (24 Aug)No count published; describes an extensive carrier network (24 Aug)
AfterShipSOC 2 Type II and ISO 27001, both named; GDPR; CIS Benchmarks; annual third-party penetration testing; HackerOne; subprocessor list; DPA (21 Aug)SLA dated 11 Apr 2025: "reasonable endeavours" to achieve 99.9% Service Uptime in any calendar month, with service credits, 30 days' maintenance notice, and a P1 to P4 response matrix. P1: first reply 2h, resolution target 6h (21 Aug)Monthly, at 5,000 shipments/mo: Essentials $239, Premium $579. Annual, at 6,000 shipments/yr: Essentials $29, Premium $59. Contact sales from 7,000/mo (21 Aug)Tracking data deleted 120 days after record creation, every plan; analytics to 3 years on Premium and Enterprise; CSV export and upload documented (21 Aug)1,400+ carriers, Tracking scope; up to 50 added monthly (21 Aug)

Figures as published on each vendor's own surfaces, read in August 2026. A dash means no published figure was read, not that none exists.

The platform reality check: Magento, Salesforce Commerce Cloud and headless

Here is where the shortlist stops surviving contact with your stack.

Malomo requires Shopify as the commerce backend. If your commerce platform is Magento, Adobe Commerce or Salesforce Commerce Cloud, it is not a candidate for you, and no amount of feature comparison changes that. It is a capable product for the merchants it was built for, and it now sits inside Redo's stack rather than standing alone.

One distinction is worth drawing precisely, because Malomo's own navigation advertises headless tracking pages. That offering is a JavaScript library that renders tracking pages for a headless storefront still running on Shopify underneath. It is not support for a non-Shopify commerce backend, and a headless build on Magento or Salesforce Commerce Cloud gets no coverage from it.

That single fact removes a third of the query you typed. It is also the most useful thing this article can tell you, because a shortlist assembled from search results is a shortlist assembled for someone else's company.

Malomo does hold one advantage worth naming, and our own breakdown for Klaviyo users concedes the same point. Its Klaviyo integration gives a Shopify brand a smoother path to editing email and SMS content out of the box, and teams that live in Klaviyo feel that difference on day one. The question at your volume is what the messaging is drawing on. AfterShip's Klaviyo integration reaches tracking, returns and AI-predicted delivery estimates sitting in one place, which is what makes a segment worth building a campaign on when you are sending across hundreds of thousands of orders a month.

The constraint also outlives the current decision. A tracking layer tied to one storefront platform becomes a second migration the moment your roadmap includes a replatform, and at this volume a replatform is rarely hypothetical.

Narvar is platform-agnostic at enterprise and deploys across the stacks this reader runs. Metapack is API-first by design, which puts the integration burden on your team and the flexibility in your hands. For a headless build, that trade is often the right one, provided you have the engineering capacity to own it.

AfterShip publishes its platform support rather than describing it: Salesforce Commerce Cloud, Magento 2, BigCommerce, Amazon Seller Central and Shopify, named on the integrations surface where a technical reviewer can check each one before a call.

What you can learn about cost before a sales call

Finance asks a simpler question than either of the other two reviewers, and it is the question that most often stalls an evaluation for three weeks.

Narvar publishes no price on any surface. Its enterprise directory listing carries the field, and the field reads "Contact vendor for pricing". Metapack publishes none either, and its pricing URL redirects to a contact form. parcelLab's pricing URL returns a 404.

Redo does publish, and it is worth being precise about how. Its own pricing page carries a per-order rate for the tracking module, read 24 August 2026, while Malomo's pricing page still carries a separate ladder of its own. Both are public. They do not agree with each other, which is its own kind of information for a buyer trying to model a renewal.

AfterShip publishes a price ladder that runs through 5,000 shipments a month, on the channel, billing term and volume basis shown in the table above. Contact-sales pricing begins at 7,000 a month. Enterprise volumes still route through sales, which is normal at this scale and honest to say.

What differs is where the conversation starts. A committee that already knows the shape of the ladder walks into that call with a model to test. A committee that has no published anchor walks in to be told, and by then the shortlist has usually narrowed itself around whoever answered fastest.

Migration and exit: getting your data back out

The question that decides how your next renewal goes is rarely on the evaluation scorecard. Not how you get in, but what it takes to leave.

Can you export your own data without opening a ticket? Redo documents scheduled CSV delivery to a private, read-only SFTP directory, on developers.redo.com. AfterShip documents CSV export and upload on the same open surface as the rest of its developer documentation, as a product capability your team can test during a trial rather than a request your account manager fulfils.

How long does the vendor keep your tracking data? AfterShip publishes an operational retention period: tracking data is deleted 120 days after the record is created, on every plan, with analytics retained up to three years on Premium and Enterprise. Metapack publishes 90 days. Redo publishes a retention section in its privacy policy, last updated 26 February 2026, which answers a legal question about personal information rather than an operational one about how long your shipment history stays queryable. Narvar and parcelLab publish the same kind of privacy-law section, neither stating a period.

Those are two different documents doing two different jobs, and a committee that treats them as interchangeable will get a surprise in year two. The same caution applies in reverse: a portability right written into a privacy policy is not a product export path, and neither should be scored as though it were the other.

Will the new vendor import your history from the old one? No. Not AfterShip, and not anyone else in this set. None of the five publishes a one-click importer for a competitor's tracking history on any surface we could read, and any implementation plan that assumes one is a plan with a gap in it.

What the market does instead is worth noticing. Redo publishes a Loop-compatible API that, in its own documentation at developers.redo.com/docs/api-reference/loop-compatible-api, read 24 August 2026, "preserves Loop's endpoint paths and response shape" so an existing Loop warehouse integration keeps working against Redo. That is a vendor building a migration ramp off a competitor's interface on purpose, and it tells you how contested this category has become.

Who does the work? AfterShip staffs enterprise onboarding with a named implementation lead and a customer success manager, which is the part of a migration plan that turns a spreadsheet of fields into a date on a calendar.

The verdict, and where to go deeper

Score the six criteria and two vendors clear all of them. Documentation is open on AfterShip, Redo and parcelLab, gated on Narvar, and partial on Metapack. Price is published by AfterShip and Redo. An export path is published by AfterShip, Redo and parcelLab.

AfterShip and Metapack are the only two publishing an operational retention period. On the depth a security review needs, covered above, AfterShip stands alone: both certifications named, and an agreement rather than an availability figure.

Narvar deserves its credit. It remains a serious enterprise platform with a large published customer footprint and a public status page, and its developer documentation is gated rather than missing, which is a commercial decision rather than an engineering gap. Our feature-by-feature comparison with Narvar sets out the rest.

Redo is the most readable vendor in this set after AfterShip, and it earned that on five surfaces a buyer can open today: developer documentation at developers.redo.com, a published per-order price, a security policy naming SOC 2, a live Trust Center, and a per-component status page on the Malomo side. Malomo is a capable Shopify-native tracking product inside Redo's stack, and for a retailer on Magento or Salesforce Commerce Cloud it is not on the shortlist at all.

For a buying committee that has to clear a security review and an engineering review, AfterShip is the vendor whose evidence goes to the depth that review needs: a named report type, a named ISO standard, and a written agreement with remedies attached.

eBay runs at a scale that makes the point better than a feature list. Its published customer story reports "200,000+ packages auto-corrected monthly", "10% improvement in EDD accuracy in 2024", and "$1M+ in operational savings" on AfterShip.

The strategic case sits in three articles rather than being repeated here. The enterprise matchup in full covers the Narvar head-to-head at length. The three-vendor enterprise verdict takes the wider landscape. The ticket-reduction comparison runs the numbers on what happens to WISMO volume after the switch.

AfterShip Tracking

Proactive shipment tracking that delights your customers, reduces WISMO tickets, and improves your delivery performance.

Book a demo

Frequently Asked Questions

How should a buying committee evaluate post-purchase vendors on public evidence?

Score each vendor on what it publishes rather than what it claims: open or gated API documentation, named certifications and status transparency, platform support beyond Shopify, published price, a documented data export path, and carrier scope with the scope of the count stated. Each of those is checkable before a sales call, which means the engineering, security and finance reviews can run in parallel with the commercial conversation instead of behind it. Vendors publish very different amounts against those six criteria, and the difference is itself a procurement signal.

Does AfterShip support Magento and Salesforce Commerce Cloud?

Yes. AfterShip publishes support for Salesforce Commerce Cloud, Magento 2, BigCommerce, Amazon Seller Central and Shopify, named on its integrations surface so a technical reviewer can check each one before a call. That matters on this shortlist because Malomo, Redo's tracking product, requires Shopify as the commerce backend and cannot be deployed on Magento or Salesforce Commerce Cloud.

What happens to your tracking data over time?

AfterShip publishes an operational retention period: tracking data is deleted 120 days after the record is created, on every plan, with analytics retained for up to three years on Premium and Enterprise. Metapack publishes a 90-day tracking cap. Redo, Narvar and parcelLab publish privacy-law retention sections covering personal information, none of which states a period, which answers a legal question rather than an operational one. A published operational period is what lets your data team plan a warehouse export schedule rather than discover a limit during an audit.

How complex is a migration to a new post-purchase platform?

Plan for a real project. None of the five publishes a one-click importer for a competitor's tracking history on any surface we could read, AfterShip included, so historical data moves by export and load rather than by switch. AfterShip documents CSV export and upload as a product capability on its open developer surface, and staffs enterprise onboarding with a named implementation lead and a customer success manager, so the plan has both a documented data path and someone accountable for the date it lands.

Updated: August 24, 2026

Share this article

Get the week's best eCommerce content

Discover more of what matters to you

Recommended from AfterShip