Security and data protection

At Upply, security is not just a technical matter — it’s at the heart of our mission and our products.
We are committed to guaranteeing every user the confidentiality, integrity, and availability of their data.

hero-securite-en
Our trust framework

Our safety principles

Our security framework is based on solid pillars:

  • Limited access: only employees with a legitimate business need can access data, following the principle of least privilege.

  • Defense in depth: multiple layers of security controls protect against threats effectively.

  • Consistent practices: unified security standards are applied across the entire company.

  • Continuous improvement: our systems are constantly evolving to remain effective and audited, without compromising user experience.

security-5
Our priority

Data protection

Protecting our users' personal data is a top priority:

  • Advanced encryption: all data is secured in transit and at rest using state-of-the-art encryption protocols.
  • Regular backups: backups are made systematically and stored securely.
  • Strict access controls: access to personal data is strictly controlled and limited to authorized persons.
  • Clear retention policy: we keep data only for as long as necessary, according to explicit deletion policies.
securite-4
securite-1 securite-1 securite-1

Personal data is used exclusively for business purposes (user management, transactional emails, billing) and all operational data linked to Upply services is permanentlypseudonymized. Data is hosted by reliable regional cloud providers, in compliance with local regulations.

securite-1

Transportdata entrusted to Upply is fully pseudonymized in order to guarantee its confidentiality and anonymity, with no possibility for a customer to trace its origin.

securite-1

Upply never shares personal or pricing data with subcontractors. Only strictly limited exchanges are carried out to enrich incomplete shipping information, for example:

  • Geoapify: conversion of addresses or postal codes into GPS coordinates.
  • PTV: calculation of road distances for our benchmarks, without storing the data transmitted.
securite-1
Our products

Product safety

Our products are designed with security in mind:

  • Secure development: regular code reviews and compliance with secure coding standards.
  • Proactive vulnerability management: frequent scans and rapid correction of detected vulnerabilities.
  • Robust authentication: use of two-factor authentication and enhanced authorization controls.
  • Continuous monitoring: our systems are monitored around the clock to detect and deal with any suspicious activity.

💡 Cloud and incident management: Upply relies on Microsoft Azure for hosting, guaranteeing high standards of compliance (see here). We have not recorded a single security incident since our inception. In the event of an incident, our procedure includes rapid rebuilding via Infrastructure as Code and transparent communication with customers.

securite-6
Our culture

Organizational safety

Security is an integral part of our corporate culture:

  • Ongoing team training in cybersecurity best practices.
  • Physical security of offices and data centers with biometric access control.
  • Dedicated team to manage and handle security incidents.
  • Rigorous evaluation of service providers prior to any collaboration to ensure our standards are maintained.
securite-2
Our promise to you

Compliance and commitment

Upply is committed to maintaining high standards of security, confidentiality and regulatory compliance. We are SOC 2 certified and RGPD compliant, and undergo annual independent audits to ensure the quality and integrity of our practices.

Regular penetration testing is carried out to detect and correct vulnerabilities, and our robust security framework has earned us an A rating on SecurityScorecard.

At Upply, cybersecurity is a cornerstone of our operations: we continually invest in advanced protection measures to ensure that your information is treated with the highest levels of confidentiality, integrity and care.

securite-3