Skip to content

Security

Security that matches the work.

ShiplyTech supports operational workflows involving employee contact information, shipping details and company-device records. Security controls should protect that information without making the return process harder to use.

Access is scoped to your organization.

Each organization's data is isolated at the database level. Users and API keys reach only their own organization's records.

  1. Customer user or API key
  2. ShiplyTech checks the organization
  3. That organization’s records

API keys resolve their own organization

An API key only reaches the organization it belongs to.

Employee links

Employees use a personal link with an unguessable token and no account. Serial-number entry through those links is rate limited.

Certificate files

Files such as certificates use short-lived, organization-checked links.

API keys and signed status notifications.

Requests to the public API authenticate with an X-API-Key header.

API keys

Organization admins create keys that start with stk_. A key is shown once, stored as a SHA-256 hash and can be rotated or revoked.

Signed webhooks

ShiplyTech signs order.status_changed notifications using HMAC-SHA256 over the raw request body, so recipients can verify that the notification came from ShiplyTech. The signature is sent in the X-Shiply-Signature header.

Webhook notifications are currently sent once without automatic retry.

API documentationWebhook documentation

  1. ShiplyTech status event
  2. Signed webhook
  3. Your system verifies the signature

Integrity of orders and records.

ShiplyTech uses the information required to operate the return workflow: employee contact details, shipping address, company return destination, equipment information and shipment status.

Prices set on the server

Order prices are recomputed on the server, not taken from the browser.

Payment separation

Card numbers are handled by Stripe, not stored by ShiplyTech. Shipping labels are bought only after payment.

Device activity history

Every device status change is logged, so your team can see what happened and when.

Record retention

Order, tracking and device-event history is kept for one year and then archived. Disposal certificates and device records are retained longer.

Security questions

Security or procurement question?

Email security@shiplytech.com for security issues and DPA requests, or legal@shiplytech.com for privacy. No response-time promise.

Trust · Privacy