Security
Security that matches the work.
ShiplyTech supports operational workflows involving employee contact information, shipping details and company-device records. Security controls should protect that information without making the return process harder to use.
Access is scoped to your organization.
Each organization's data is isolated at the database level. Users and API keys reach only their own organization's records.
- Customer user or API key
- That organization’s records
API keys resolve their own organization
An API key only reaches the organization it belongs to.
Employee links
Employees use a personal link with an unguessable token and no account. Serial-number entry through those links is rate limited.
Certificate files
Files such as certificates use short-lived, organization-checked links.
API keys and signed status notifications.
Requests to the public API authenticate with an X-API-Key header.
API keys
Organization admins create keys that start with stk_. A key is shown once, stored as a SHA-256 hash and can be rotated or revoked.
Signed webhooks
ShiplyTech signs order.status_changed notifications using HMAC-SHA256 over the raw request body, so recipients can verify that the notification came from ShiplyTech. The signature is sent in the X-Shiply-Signature header.
Webhook notifications are currently sent once without automatic retry.
- ShiplyTech status event
- Your system verifies the signature
Integrity of orders and records.
ShiplyTech uses the information required to operate the return workflow: employee contact details, shipping address, company return destination, equipment information and shipment status.
Prices set on the server
Order prices are recomputed on the server, not taken from the browser.
Payment separation
Card numbers are handled by Stripe, not stored by ShiplyTech. Shipping labels are bought only after payment.
Device activity history
Every device status change is logged, so your team can see what happened and when.
Record retention
Order, tracking and device-event history is kept for one year and then archived. Disposal certificates and device records are retained longer.
Security questions
Security or procurement question?
Email security@shiplytech.com for security issues and DPA requests, or legal@shiplytech.com for privacy. No response-time promise.