Purpose
This policy defines the information security controls implemented within Global Logistics Software (GLS). Its objective is to reduce the risk of unauthorised access, disclosure, loss or misuse of information while supporting legitimate operational activity.
Scope
This policy applies to all GLS systems, environments and services, including personal, operational and commercial data processed on behalf of customers.
Security principles
- security-by-design rather than reactive control
- strict logical tenant isolation
- least-privilege access to data and functionality
- traceability of administrative and sensitive actions
- encryption of data in transit and at rest
Core security controls
Access control
Access to GLS requires authenticated user accounts. Authorisation is role-based and limits users to the minimum functionality required for their responsibilities. Elevated privileges require explicit assignment and are not granted by default.
Tenant isolation
Customer data is logically segregated by tenant. All access to operational data requires a valid tenant context to prevent accidental or deliberate cross-tenant exposure.
Traceability and logging
Security-relevant user and system actions are logged to support monitoring, investigation and audit. Logs are retained in a manner intended to provide evidentiary value during security reviews or regulatory enquiries.
Encryption
Industry-standard cryptographic controls are used to protect data transmitted between systems and to secure stored customer data.
Secure development and change control
Platform changes follow controlled development and release processes designed to reduce the introduction of unreviewed or insecure behaviour.
Resilience and backup
Security is treated in conjunction with availability. Backup, recovery and continuity measures are implemented to help ensure that security incidents do not result in irreversible data loss.
Platform authority and global administrative control
GLS operates a restricted platform-level authority model to support security operations, regulatory compliance and incident response. This authority is separate from customer tenancy and is not exposed through standard user or tenant administration.
Global Super User (GSU)
A Global Super User (GSU) is a tightly controlled platform authority role used solely for security, continuity and regulatory purposes. The role exists to protect platform integrity and to fulfil legal obligations under frameworks such as NIS2 and ISO 27001.
Permitted activities
- management of platform security configuration
- execution of incident response actions, including access restriction
- support of lawful and regulatory data preservation requests
- review of audit metadata relating to platform operation
Explicit restrictions
Global Super Users are technically and procedurally restricted from performing tenant-level commercial or operational activity.
- no routine access to customer business data
- no modification of shipments, pricing, invoices or financial records
- no circumvention of billing or payment systems
- no deletion or alteration of audit logs
- no creation of additional Global Super User accounts
Creation, access and oversight
Global Super User accounts are created only as part of controlled deployment or operational processes and are not provisioned through user interfaces. Elevated access is protected through strong authentication controls.
All actions performed under this authority are logged, reviewed and subject to oversight to ensure appropriate and proportionate use.
Alignment with regulatory expectations
The controls described in this policy support alignment with common security frameworks and regulatory obligations, including NIS2 and GDPR security requirements. GLS forms part of a broader customer security and governance environment and does not replace internal organisational controls.
Customer responsibilities
Customers remain responsible for:
- assigning appropriate internal roles and permissions
- protecting local systems, devices and credentials
- ensuring lawful and legitimate use of data
- promptly reporting suspected security incidents
Limitations
No technical system can eliminate all security risk. Threats, technology and regulatory expectations evolve, and security controls will continue to develop over time.
Review
This policy is reviewed at least annually or sooner where material changes occur in platform design, regulation or the threat environment.