Skip to content
SECURITY & TRUST

Security is part of the product, not an add-on

We handle addresses, business data and payments. Here is how we protect them.

Account security

  • Passwords hashed with BCrypt
  • Short-lived JWT access tokens
  • Rotating refresh tokens with reuse detection
  • Session metadata to spot suspicious sign-ins

Access control

  • Role-based access control (RBAC)
  • Strict separation of customer and back-office access
  • Audit trail for sensitive actions

Data protection

  • TLS encryption in transit
  • Personal and financial data masked in logs
  • Errors never expose internal details
  • Carrier credentials isolated per environment

Privacy & compliance

  • Designed for KVKK and GDPR
  • Data minimization and retention limits
  • Data processing agreements for business customers

AI safety

  • Only task-relevant data is sent to the model
  • Schema validation before any action
  • Human approval for money and customer messages
  • Built on Anthropic’s commercial API

Responsible disclosure

  • Found a vulnerability? Email us at info@kodlagonder.com
  • We reply within 3 business days
  • Please do not access other users’ data

Ready to ship smarter?

Join the early-access program and help shape the AI-native shipping platform.