Security

Security in CargoPay is not a feature added to the platform. It is how every module, workflow and transaction is built. From the moment a company applies to the moment money moves, each step is checked rather than assumed.

The threats this is built against

Impersonation

Fraud in road freight generally works by pretending to be a legitimate haulier for long enough to be handed a load.

Subcontracting chains

The further a load travels down a chain of subcontractors, the less anyone knows about who is actually driving it.

Payment redirection

An invoice with altered bank details is the cheapest attack there is, and it lands after the work is already done.

Multi-layer security architecture

Each tier of the platform has its own controls, from entry to the verified network through to the individual transaction.

Layer 1

Company verification

Before any operator accesses the CargoPay network, it undergoes a rigorous, multi-step verification process. This is not a checkbox exercise it is the primary defence against fraudulent actors infiltrating your supply chain.

Company registration validation

Certificate of incorporation, commercial register extract, and VAT registration cross-referenced against official EU databases.

Operational credential verification

EU Community licence for international road haulage, transport operator licence, and professional competence certificate validated against issuing authorities.

Representative authorisation

Identity verification for authorised signatories prevents unauthorised account creation and ensures chain-of-command integrity.

View Required Documentation
Verification process illustration
Layer 2

Secure payment processing

Every payment flows through Stripe one of the world's leading payment infrastructure providers, holding PCI DSS Level 1 certification, the highest security standard available in the payments industry.

CargoPay never stores your payment data

Card numbers, CVVs, and sensitive payment credentials are handled exclusively by Stripe's certified infrastructure. CargoPay holds zero sensitive payment data on its servers.

  • End-to-end payment encryption across all lanes
  • Stripe Radar machine-learning fraud detection
  • 3D Secure Strong Customer Authentication (SCA)
  • Real-time transaction risk scoring per consignment
Secure payment processing
Layer 3

Controlled communication channels

Payment requests are delivered by email only. This is a deliberate, security-driven architectural decision not a limitation.

Public links can be intercepted, shared unintentionally, or weaponised as phishing vectors. Email provides a verifiable, auditable delivery channel that maintains the transaction within a controlled, traceable environment from dispatch to payment.

Email delivery

Verifiable, documented, auditable

Public links

Interception risk, no audit trail

Controlled communication channels
Layer 4

Transaction monitoring & fraud detection

CargoPay monitors every transaction for patterns indicative of fraudulent activity proactively, in real time, not retrospectively after the damage is done.

Behavioural analytics

Payment behaviour profiles analysed in real time to flag deviations from established operational patterns and lane histories.

Velocity checks

Rate limiting and velocity analysis detect anomalous transaction volumes or frequency spikes indicative of coordinated fraud.

Company checks

Continuous monitoring of company licences, fleet registrations, and interaction patterns within the verified network.

Transaction monitoring dashboard

Data protection & GDPR compliance

CargoPay operates in full compliance with applicable data protection regulations, including the General Data Protection Regulation (GDPR). Company data, transaction records, and verification documents are protected according to the highest standards for confidentiality and integrity.

  • GDPR Article 5 data minimisation principles enforced
  • Verification documents used solely for identity verification
  • Zero data sharing with third parties without explicit consent
  • eFTI Regulation (EU) 2020/1056 alignment for digital freight documentation

Encrypted secrets

Credentials and provider secrets are encrypted with AES-256-GCM. Card data never reaches us at all.

Encrypted in transit

Every connection to the platform and to our payment provider runs over HTTPS.

Data minimisation

Only necessary data collected, retained only for the legally required duration

Audit trail

Complete transaction and access logs for compliance reporting and dispute resolution

Once you are inside

Verification decides who gets in. These decide what they can reach afterwards.

Your data is scoped to your organisation

Records are filtered by organisation in the queries themselves, not hidden in the interface. Another company cannot read your shipments by changing a URL.

Permissions checked per action

Every guarded action asserts a role and a privilege before it runs, so a carrier account cannot reach a shipper action, or an admin one.

Forms carry request tokens

State-changing requests are validated against a per-session token, so a form cannot be submitted on your behalf from somewhere else.

Login is rate limited and locked out

Repeated failures throttle by address and lock the account itself, so a stolen password list cannot be tried against you at speed.

Documents are signed, not just stored

The eCMR is signed through a qualified signature provider, and the document records who signed and when. We hold the record, not the signing authority.

Actions leave an audit trail

Access and changes are logged, which is what makes a dispute answerable from the record rather than from memory.

Operate with the security your freight business demands

CargoPay's multi-layer security architecture is engineered for the realities of European road freight where fraud is sophisticated, margins are tight, and trust must be verified at every node of the supply chain.