Early access for UK transport operators View the Founding Customer Programme

Information security policy

GLS is designed so that security is embedded into the platform architecture rather than applied as an afterthought. Access control, segregation of data and traceability are core design principles used to protect operational and commercial information.

Version: 0.7 Last reviewed: Jan 2026 Review cycle: Annual or upon material change

Purpose

This policy defines the information security controls implemented within Global Logistics Software (GLS). Its objective is to reduce the risk of unauthorised access, disclosure, loss or misuse of information while supporting legitimate operational activity.

Scope

This policy applies to all GLS systems, environments and services, including personal, operational and commercial data processed on behalf of customers.

Security principles

  • security-by-design rather than reactive control
  • strict logical tenant isolation
  • least-privilege access to data and functionality
  • traceability of administrative and sensitive actions
  • encryption of data in transit and at rest

Core security controls

Access control

Access to GLS requires authenticated user accounts. Authorisation is role-based and limits users to the minimum functionality required for their responsibilities. Elevated privileges require explicit assignment and are not granted by default.

Tenant isolation

Customer data is logically segregated by tenant. All access to operational data requires a valid tenant context to prevent accidental or deliberate cross-tenant exposure.

Traceability and logging

Security-relevant user and system actions are logged to support monitoring, investigation and audit. Logs are retained in a manner intended to provide evidentiary value during security reviews or regulatory enquiries.

Encryption

Industry-standard cryptographic controls are used to protect data transmitted between systems and to secure stored customer data.

Secure development and change control

Platform changes follow controlled development and release processes designed to reduce the introduction of unreviewed or insecure behaviour.

Resilience and backup

Security is treated in conjunction with availability. Backup, recovery and continuity measures are implemented to help ensure that security incidents do not result in irreversible data loss.

Platform authority and global administrative control

GLS operates a restricted platform-level authority model to support security operations, regulatory compliance and incident response. This authority is separate from customer tenancy and is not exposed through standard user or tenant administration.

Global Super User (GSU)

A Global Super User (GSU) is a tightly controlled platform authority role used solely for security, continuity and regulatory purposes. The role exists to protect platform integrity and to fulfil legal obligations under frameworks such as NIS2 and ISO 27001.

Permitted activities

  • management of platform security configuration
  • execution of incident response actions, including access restriction
  • support of lawful and regulatory data preservation requests
  • review of audit metadata relating to platform operation

Explicit restrictions

Global Super Users are technically and procedurally restricted from performing tenant-level commercial or operational activity.

  • no routine access to customer business data
  • no modification of shipments, pricing, invoices or financial records
  • no circumvention of billing or payment systems
  • no deletion or alteration of audit logs
  • no creation of additional Global Super User accounts

Creation, access and oversight

Global Super User accounts are created only as part of controlled deployment or operational processes and are not provisioned through user interfaces. Elevated access is protected through strong authentication controls.

All actions performed under this authority are logged, reviewed and subject to oversight to ensure appropriate and proportionate use.

Alignment with regulatory expectations

The controls described in this policy support alignment with common security frameworks and regulatory obligations, including NIS2 and GDPR security requirements. GLS forms part of a broader customer security and governance environment and does not replace internal organisational controls.

Customer responsibilities

Customers remain responsible for:

  • assigning appropriate internal roles and permissions
  • protecting local systems, devices and credentials
  • ensuring lawful and legitimate use of data
  • promptly reporting suspected security incidents

Limitations

No technical system can eliminate all security risk. Threats, technology and regulatory expectations evolve, and security controls will continue to develop over time.

Review

This policy is reviewed at least annually or sooner where material changes occur in platform design, regulation or the threat environment.