Enterprise Tracking Platforms: A 2026 Security & Compliance Verdict

Updated: August 28, 2026

·

18 mins read

The 2026 Boardroom Question: Is Our Post-Purchase Data a Liability or an Asset?

Your operations team has found a tracking platform they like. Your CMO loves the branded experience. But you've been handed the security questionnaire. Your job isn't to evaluate features; it's to evaluate risk, and this year the risk has a number on it: IBM puts supply chain compromise, where a business partner is breached and becomes the attack vector, as the single most expensive factor increasing the cost of a breach, adding USD 227,250 on average. You are about to onboard a business partner. Let's get straight to the facts.

That figure comes from the IBM Cost of a Data Breach Report 2026, published on 29 July 2026, which examined 602 breached organizations across incidents occurring between March 2025 and February 2026. The same study puts the global average cost of a breach at USD 4.99 million and the US average at USD 11.5 million.

Read the ranking again, because the ordering is the point. Of every cost factor IBM measured, the one that added the most was a partner being compromised and becoming the route in.

A tracking platform sits precisely there. It ingests order records, delivery addresses, contact details and shipment events for every customer you have, and it holds an authenticated connection into your commerce stack. That puts it in the same review bracket as any other system holding customer records, and it is why enterprise tracking platforms security belongs on your desk rather than in a logistics evaluation.

Your operations team is scoring workflow. You are scoring blast radius.

A CISO's Framework for Evaluating Tracking Platform Security

A vendor security questionnaire covers a lot of ground, and much of it does not discriminate between platforms in this category. Five areas do. The rest of this article works through them in order and applies the same standard to each.

  • Certifications and compliance. Does an independent auditor attest to the controls, and can you read the contract terms that bind the vendor to them?
  • Data architecture and encryption. Where does the data live, how is it protected in motion and at rest, and which third parties touch it?
  • Platform reliability and availability. What does the contract actually commit to, and what is the remedy when the commitment is missed?
  • Identity and access management. How do your people authenticate, what can each of them see, and what record survives afterward?
  • API and integration security. How is machine access authenticated, and can your engineers inspect the integration surface before you sign anything?

One test runs through all five: can you open a page and verify the claim yourself, without booking a sales call? A vendor that clears that bar has handed you something you can attach to a risk file. A vendor that does not has handed you a meeting invitation.

Every AfterShip security claim in this article links to the public AfterShip page it comes from, so you can open it and check it yourself.

Pillar 1: Certifications & Compliance (SOC 2, ISO 27001, GDPR)

Start with what the two credentials actually establish, because the questionnaire line reading "SOC 2 / ISO 27001 (Y/N)" flattens a real distinction.

SOC 2 Type II is an attestation. An independent auditor tests a service organization's controls across a defined period and issues a report describing how those controls operated over that window. It produces a report rather than a certificate, and a vendor selling you "SOC 2 certification" has already told you something about its precision.

ISO 27001 works on a different axis. It is a certification against a management-system standard: the vendor builds an information security management system, an accredited body audits that system, and the certification attests that it meets the standard's requirements. One credential tells you controls were tested over time. The other tells you a governing system exists and is audited against a published benchmark. A serious review wants both, for different reasons.

AfterShip's security and privacy controls are verified in a SOC 2 Type II report. AfterShip also holds ISO 27001 certification, the global standard for information security management systems (ISMS) controls. Both credentials are published on the AfterShip Trust Center, alongside the rest of its comprehensive security and compliance posture.

The detailed reports are available on request, through the AfterShip sales and security team. For a reviewer in your position that is a normal control rather than an obstacle. Stating the access path is more useful to you than implying self-serve availability, because it tells you exactly what to ask for and whom to ask.

Regulatory readiness sits in a different document. The public Data Processing Agreement is where GDPR and CCPA commitments stop being marketing language and become contract language, setting out AfterShip's role as processor, the instructions it acts under, and its obligations on data subject access requests. Your privacy counsel can read those terms today, before procurement opens a file.

Vendors in this category deliver evidence differently. Some publish a request-gated portal listing certificates, test reports and policies. Some name their auditor on a public documentation page. AfterShip publishes its credentials, its Trust Center, its status page, its Data Processing Agreement and its sub-processor list openly, and provides the detailed reports on request.

In an enterprise tracking platforms security review, a claim you can attach to the file outranks a claim you have to relay. A SOC 2 compliant tracking platform that publishes its evidence and its contract terms gives you the first kind.

Pillar 2: Data Architecture & Encryption

Start with the physical question, because every downstream control depends on the answer. The AfterShip Services are hosted on Google Cloud Platform and Amazon Web Services in the United States. Both providers undergo independent verification of their own security, privacy and compliance controls, and the Trust Center states the hosting arrangement in those terms.

On data encryption in transit and at rest, the published record names the specifics instead of the category: TLS 1.2 for data in transit, AES-256 for data at rest. Named algorithms are testable. "Bank-grade encryption" is not.

The strongest disclosure in AfterShip's documentation set is the one this category usually treats as a footnote. The public sub-processors list names twelve vendors, and every row carries both the processing location and the international transfer mechanism governing it, with Standard Contractual Clauses declared on each transfer. Your reviewer can read the fourth-party map before the contract is drafted, rather than reconstructing it from questionnaire answers afterward.

That disclosure does real work for you. Fourth-party risk is where most vendor questionnaires stall, because the answer usually arrives as a name list with no locations and no transfer basis, and your privacy team then has to chase both. A list that already carries all three fields turns a two-week exchange into a document review.

The Data Processing Agreement carries the incident commitment. AfterShip notifies of a personal data breach within seventy-two hours of becoming aware, unless the breach is unlikely to pose a risk to the rights and freedoms of individuals. Retention works the same way: how long personal data is held is governed by the controller's instructions and AfterShip's retention policy under the DPA, so the answer to "how long do you keep it" sits in your contract instead of a marketing page.

The question of data residency deserves harder treatment than most evaluations give it. Residency, retention and sub-processor change rights are all contract-level terms that vary by vendor and by agreement, and none of them is settled by a badge on a homepage. Put all three to every vendor on your shortlist, and read each one's sub-processor list before you sign anything.

AfterShip's residency answer is a United States footprint, stated plainly and without a roadmap promise attached to it. Whether that fits your regulatory profile is your call, and the published record gives you everything you need to make it in one sitting.

Pillar 3: Platform Reliability & Availability

Availability gets answered with a status page far more often than it should. A status page is telemetry. A contract is a commitment, and only one of the two carries a remedy when it is missed.

AfterShip commits to 99.9% monthly Service Uptime, measured on the AfterShip API and backed by a service-credit remedy, under the Enterprise SLA last updated 11 April 2025.

Read the scope before you record the number. The measured service is the AfterShip API. Branded tracking page rendering and notification delivery sit outside that measurement, and any vendor's availability figure deserves the same scoping question from you.

The remedy has a defined structure. Credits scale with the severity of the outage band, are capped at one twelfth of annualised recurring fees across any twelve-month window, must be requested in writing, and are the sole remedy for missed availability. This is delivered under the Enterprise SLA terms rather than on self-serve plans, which is worth confirming before procurement quotes the figure back to you.

Convert the percentage into an error budget before you accept it. That commitment allows roughly 43.2 minutes of unavailability per month. Scheduled maintenance sits outside that budget, capped at up to eight hours per session, twice per calendar month, on thirty days' notice.

Underneath the commitment sits a layered control set, all of it published on the AfterShip Trust Center: annual third-party penetration testing, a bug bounty program through HackerOne, automated vulnerability scanning, Cloudflare WAF, and 24/7 security monitoring and incident response.

The public status page is the operational record, and it is honest about its own limits. Numeric uptime is published for the API and website components, the longest built-in window is one month, and the courier tracking and shipping components report status without a percentage attached. Note what that means for your evidence pack: the status page will not hand you a long-range availability trend, so if your review requires one, collect the monthly views over the course of your evaluation or ask for the figures during the security review.

Availability at enterprise volume is a different proposition from availability in a demo tenant: eBay saved millions of dollars and improved its valid tracking rate by over 20% on AfterShip Tracking.

eBay

“We work with hundreds of carriers globally and know that shipping tracking has a high level of entropy. We appreciate that AfterShip has a superior monitoring system that proactively identifies and quickly resolves our tracking issues about three times faster without our involvement.”

Skyler Loth, Product Manager, eBay Shipping Tracking

Read their story →

Rakuten France's Director of Customer Relationship, Habib-Sylvain Gourguet, put the integration risk plainly: "AfterShip is the most advanced shipment tracking solution in the market. It only took 1-2 weeks for our engineers to implement."

For a reviewer scoring reliability, the artifact that matters is the one with a remedy attached to it. AfterShip publishes both: the contract that commits, and the page that records how the commitment is being met.

Pillar 4: Identity & Access Management

Take the identity questions in the order that decides the most risk. Organization-wide two-factor and multi-factor authentication enforcement is available across AfterShip plans, which keeps the control that matters most against credential theft outside any tier upgrade conversation.

SSO/SAML integration comes next. AfterShip supports SAML 2.0, with OIDC available at the Enterprise tier, so your identity provider stays the authority on who reaches the platform and your existing conditional access policies keep applying to it.

AfterShip offers SSO, RBAC, and a centralized admin console. Role-based access control is administered from that console, which is also where your team configures granular access controls and audit logs across the organization. Strong password requirements apply to accounts that authenticate locally, which matters during the window before your SSO rollout completes.

Audit logs are available on the Team and Enterprise plans and are viewable for up to 180 days. They record support-agent impersonation events, so if an AfterShip support agent enters your account, the entry is logged and you can read it. That window is what is published, so plan your own log export if your retention policy runs longer.

AfterShip — Organization security settings
AfterShip — Organization security settings

On deprovisioning, the useful answer is the mechanism rather than the aspiration. AfterShip provisions users through SAML SSO, and de-activation is performed centrally from the admin console. There is no automated directory-sync removal to describe here, so build the offboarding step into your own runbook and walk through it during implementation. Stating that plainly is more useful to a reviewer than a capability claim that fails its first audit sample.

Every control in this pillar is documented on a public AfterShip page your identity team can read before a contract is signed, which is the same standard the rest of this evaluation has been held to.

Pillar 5: API & Integration Security

For a CTO, the API is the product. It is also the exact scope of the availability commitment in Pillar 3, which means the uptime figure and the integration surface are describing the same system.

Authentication is API key based. Rate limiting is applied at the platform level to protect availability across tenants, and your integration team should size retry and backoff behaviour against it during implementation rather than discovering the ceiling in production.

The part that matters most to your review is the part that costs nothing to check. AfterShip's API documentation is public and ungated. Your engineers can read the endpoints, the authentication model, the webhook payloads and the error semantics today, with no NDA, no sales conversation and no provisioned sandbox.

That shortens a security review. An integration surface your team can inspect before the first call is one they can threat-model before the first call, and the findings arrive before the terms are settled. You can review the security protocols for our Tracking API in the same documentation your developers will build against.

The 2026 Security Verdict: AfterShip vs. Narvar vs. ParcelLab

Seven criteria decide this evaluation. The table below is the record for a parcel tracking platforms security comparison 2026, built from each vendor's own public pages, read on 27 August 2026.

CriteriaAfterShipNarvarParcelLab
SOC 2 Type II (attestation status)Verified in a SOC 2 Type II reportListed on trust portal; document behind access requestPublished; auditor named publicly
ISO 27001 (certification status)Holds ISO 27001 certificationListed on trust portal; document behind access requestNot claimed on any surface it controls
Public Trust CenterPublic, no access requestPortal gates 13 of 14 documentsPublic documentation page
Public Status PagePublic; longest built-in window one monthPublic; 90-day windowPublic; 90-day window
Published Uptime SLA (Y/N plus percentage)Yes, 99.9% monthly on the AfterShip APIYes, 99% on a 2017 documentSLA available on request; no percentage published
SSO/SAML SupportSAML 2.0, OIDC at Enterprise tierNot documented publiclyDocuments SAML 2.0 and OIDC
GDPR Data Processing Agreement and Residency OptionsPublic DPA; US hosting; SCCs on every transferUS hostingGermany hosting

AfterShip pairs publicly verifiable credentials, a SOC 2 Type II report and ISO 27001 certification, with a public Trust Center, a public status page, a public Data Processing Agreement and a public sub-processor list carrying Standard Contractual Clauses on every transfer, and provides the detailed reports on request. That is a strong, publicly verifiable baseline to bring into a procurement review.

Three points resolve in AfterShip's favour on evidence a reader can confirm in a single click. Sub-processor disclosure is the first, because every row on AfterShip's list carries both a processing location and a transfer mechanism, at a level of detail neither competitor matches. Published encryption standards are the second, because AfterShip names its algorithms for data in transit and at rest, and neither competitor publishes an encryption algorithm at all. The third is the contractual commitment on availability, where AfterShip commits to 99.9% monthly Service Uptime and Narvar's published service level agreement, dated 22 September 2017, commits to 99%.

On Narvar compliance the picture is mixed rather than absent. Its trust portal lists ISO/IEC 27001 and SOC 2, and thirteen of the fourteen documents behind it require an access request before you can read them. Budget for that step in your evaluation timeline, because an access request adds a dependency you do not control, and it lands during the weeks when your review is already under the most schedule pressure.

parcelLab publishes a SOC 2 Type II and names its auditor, and it claims no ISO 27001 on any surface it controls. It also documents SAML 2.0 and OIDC, where Narvar does not document its single sign-on publicly.

Two concessions belong in any scorecard you would defend in front of a risk committee. For enterprises deeply embedded with legacy systems, Narvar has historically been a common choice. However, for organizations building a modern, composable, and secure tech stack, AfterShip's publicly verifiable security model provides the evidence a reviewer can act on without a sales call.

The second concession runs on evidence delivery. Narvar's trust portal catalogues more artifacts than AfterShip publishes and parcelLab names its SOC 2 auditor where AfterShip does not, though a catalogue behind an access request is not evidence until the request is granted.

AfterShip is the choice for an enterprise that needs to verify a vendor rather than trust one. Its credentials, its Trust Center, its status page, its Data Processing Agreement and its sub-processor list are all public and checkable, and the detailed reports are available on request. For the full competitive picture beyond security, there is a broader feature-by-feature comparison against Narvar.

Frequently Asked Questions

Is AfterShip SOC 2 compliant?

AfterShip's security and privacy controls are verified in a SOC 2 Type II report. SOC 2 Type II is an attestation rather than a certificate: an independent auditor tests controls across a defined period and issues a report on how they operated over that window. The credential is published on the AfterShip Trust Center, and the detailed report is available on request through the AfterShip sales and security team.

Does AfterShip support SSO?

AfterShip supports SAML 2.0 single sign-on, with OIDC available at the Enterprise tier, so your identity provider remains the authority on who reaches the platform. Organization-wide two-factor and multi-factor authentication enforcement is available across plans, and role-based access control is administered from the centralized admin console. AfterShip offers SSO, RBAC, and a centralized admin console.

What is AfterShip's uptime SLA?

AfterShip commits to 99.9% monthly Service Uptime, measured on the AfterShip API, backed by a service-credit remedy under the Enterprise SLA last updated 11 April 2025. The public status page publishes numeric uptime for the API and website components.

Is AfterShip GDPR compliant?

AfterShip publishes a Data Processing Agreement covering its role as processor, the instructions it acts under, and its obligations on data subject access requests, alongside CCPA commitments. Under the DPA, AfterShip notifies of a personal data breach within seventy-two hours of becoming aware, unless the breach is unlikely to pose a risk to the rights and freedoms of individuals. Its public sub-processor list declares Standard Contractual Clauses on every international transfer. Every one of those terms sits in a public document your privacy counsel can read before procurement opens a file.

Ready for Your Security Review?

Everything above resolves to a page you can open before you sign anything:

  • A SOC 2 Type II report and ISO 27001 certification, published on the Trust Center, with the detailed reports available on request.
  • Hosting on Google Cloud Platform and Amazon Web Services in the United States, with TLS 1.2 in transit and AES-256 at rest.
  • A sub-processor list naming twelve vendors, each row carrying a processing location and Standard Contractual Clauses.
  • A contractual monthly Service Uptime commitment on the AfterShip API, backed by a service-credit remedy under the Enterprise SLA.
  • Organization-wide MFA enforcement, SAML 2.0 with OIDC at the Enterprise tier, RBAC, and audit logs viewable for up to 180 days.
AfterShip Tracking

Proactive shipment tracking that delights your customers, reduces WISMO tickets, and improves your delivery performance.

Start a security review with our team

When your questionnaire calls for the detailed reports, request AfterShip's security documentation or start a security review with our team. If your engineers want to walk the integration surface first, speak with a solutions engineer.

An enterprise tracking platforms security decision has to be defended line by line, to people who were not in the demo. AfterShip is built to be defended that way.

Updated: August 28, 2026

Share this article

Get the week's best eCommerce content

Discover more of what matters to you

Recommended from AfterShip