Security
Security in CargoPay is not a feature added to the platform. It is how every module, workflow and transaction is built. From the moment a company applies to the moment money moves, each step is checked rather than assumed.
The threats this is built against
Impersonation
Fraud in road freight generally works by pretending to be a legitimate haulier for long enough to be handed a load.
Subcontracting chains
The further a load travels down a chain of subcontractors, the less anyone knows about who is actually driving it.
Payment redirection
An invoice with altered bank details is the cheapest attack there is, and it lands after the work is already done.
Multi-layer security architecture
Each tier of the platform has its own controls, from entry to the verified network through to the individual transaction.
Company verification
Before any operator accesses the CargoPay network, it undergoes a rigorous, multi-step verification process. This is not a checkbox exercise it is the primary defence against fraudulent actors infiltrating your supply chain.
Company registration validation
Certificate of incorporation, commercial register extract, and VAT registration cross-referenced against official EU databases.
Operational credential verification
EU Community licence for international road haulage, transport operator licence, and professional competence certificate validated against issuing authorities.
Representative authorisation
Identity verification for authorised signatories prevents unauthorised account creation and ensures chain-of-command integrity.
Secure payment processing
Every payment flows through Stripe one of the world's leading payment infrastructure providers, holding PCI DSS Level 1 certification, the highest security standard available in the payments industry.
CargoPay never stores your payment data
Card numbers, CVVs, and sensitive payment credentials are handled exclusively by Stripe's certified infrastructure. CargoPay holds zero sensitive payment data on its servers.
- End-to-end payment encryption across all lanes
- Stripe Radar machine-learning fraud detection
- 3D Secure Strong Customer Authentication (SCA)
- Real-time transaction risk scoring per consignment
Controlled communication channels
Payment requests are delivered by email only. This is a deliberate, security-driven architectural decision not a limitation.
Public links can be intercepted, shared unintentionally, or weaponised as phishing vectors. Email provides a verifiable, auditable delivery channel that maintains the transaction within a controlled, traceable environment from dispatch to payment.
Email delivery
Verifiable, documented, auditable
Public links
Interception risk, no audit trail
Transaction monitoring & fraud detection
CargoPay monitors every transaction for patterns indicative of fraudulent activity proactively, in real time, not retrospectively after the damage is done.
Behavioural analytics
Payment behaviour profiles analysed in real time to flag deviations from established operational patterns and lane histories.
Velocity checks
Rate limiting and velocity analysis detect anomalous transaction volumes or frequency spikes indicative of coordinated fraud.
Company checks
Continuous monitoring of company licences, fleet registrations, and interaction patterns within the verified network.
Data protection & GDPR compliance
CargoPay operates in full compliance with applicable data protection regulations, including the General Data Protection Regulation (GDPR). Company data, transaction records, and verification documents are protected according to the highest standards for confidentiality and integrity.
- GDPR Article 5 data minimisation principles enforced
- Verification documents used solely for identity verification
- Zero data sharing with third parties without explicit consent
- eFTI Regulation (EU) 2020/1056 alignment for digital freight documentation
Encrypted secrets
Credentials and provider secrets are encrypted with AES-256-GCM. Card data never reaches us at all.
Encrypted in transit
Every connection to the platform and to our payment provider runs over HTTPS.
Data minimisation
Only necessary data collected, retained only for the legally required duration
Audit trail
Complete transaction and access logs for compliance reporting and dispute resolution
Once you are inside
Verification decides who gets in. These decide what they can reach afterwards.
Your data is scoped to your organisation
Records are filtered by organisation in the queries themselves, not hidden in the interface. Another company cannot read your shipments by changing a URL.
Permissions checked per action
Every guarded action asserts a role and a privilege before it runs, so a carrier account cannot reach a shipper action, or an admin one.
Forms carry request tokens
State-changing requests are validated against a per-session token, so a form cannot be submitted on your behalf from somewhere else.
Login is rate limited and locked out
Repeated failures throttle by address and lock the account itself, so a stolen password list cannot be tried against you at speed.
Documents are signed, not just stored
The eCMR is signed through a qualified signature provider, and the document records who signed and when. We hold the record, not the signing authority.
Actions leave an audit trail
Access and changes are logged, which is what makes a dispute answerable from the record rather than from memory.
Operate with the security your freight business demands
CargoPay's multi-layer security architecture is engineered for the realities of European road freight where fraud is sophisticated, margins are tight, and trust must be verified at every node of the supply chain.