Legal & Security

Access Control & Least Privilege Policy

Effective date: September 3, 2026 · Last updated: September 3, 2026

This Access Control & Least Privilege Policy (the "Policy") describes how MyShipPilot LLC ("MyShipPilot", "we") restricts access to the systems, applications, and data that support the MyShipPilot shipping platform. It applies to all personnel, contractors, and service accounts that interact with MyShipPilot systems on our behalf.

1. Scope of restricted resources

Access to the following is restricted to authorized personnel based on job responsibilities and a documented business need:

  • Production and development systems, hosting, and runtime environments.
  • Administrative functions and internal staff tooling.
  • Customer information, including account, shipment, and contact data.
  • Payment and shipping operational data, including labels, payments, refunds, and carrier billing adjustments.
  • Credentials, secrets, API keys, and service-role tokens.
  • Security logs, audit records, and configuration that affects access control itself.

2. Least privilege

Users and personnel receive only the minimum permissions necessary to perform their job responsibilities. Privileged and administrative access is limited to a small number of authorized individuals and is enforced separately from ordinary user access. Customer accounts never carry administrative privileges, and personnel cannot grant themselves an elevated role.

3. Authentication and multi-factor authentication

Access to MyShipPilot systems requires strong authentication. Passwords must meet minimum-strength requirements, and known compromised passwords are blocked at signup and password reset. Privileged and administrative actions require multi-factor authentication (MFA) where implemented. We enforce time-based one-time password (TOTP) authenticator factors for administrative access, and higher-assurance sensitive administrative actions require an elevated, second-factor-verified session before they may be performed.

4. Role-based authorization and server-side enforcement

Authorization is role-based and enforced on the server, not in the browser. Access to administrative data and functions is gated by a server-side role check that verifies the caller's assigned role using a security-protected function and the caller's own authenticated session before any privileged data is loaded. Row-level security (RLS) policies further restrict data at the database layer, so that administrative records are only available to authorized roles and each customer can access only their own data.

Simply navigating to an administrative URL does not grant access. Internal staff pages are placed behind a route-level authorization gate that performs the server-side role check before any administrative interface is rendered. Non-admin users who attempt to reach an administrative page are denied and redirected away from it. A signed-in customer cannot render administrative controls by typing a URL, regardless of their session.

5. Access review and revocation

Access is reviewed when a person's role or responsibilities change. Administrative and privileged access is removed promptly when it is no longer required, including when a person leaves MyShipPilot or changes role. Service-account credentials and secrets are stored only in protected, server-side configuration and are rotated or revoked when access ends or when exposure is suspected.

6. No credential or account sharing

Sharing of credentials, accounts, or authentication factors is prohibited. Each individual is responsible for activity performed under their own identity. Administrative access is tied to a named, authenticated individual and is never shared between users.

7. Logging and monitoring

Sensitive administrative and security-relevant activity is logged where applicable. Access to protected data through privileged functions is recorded in an access log that captures the actor, role, action, and resource. Log records are written by the system and are not user-editable, and they may be reviewed for unauthorized or anomalous activity. Logs do not contain sensitive secrets or payment card data.

Access-log records are retained for two years, and the log is reviewed at least every fourteen days. Each review is recorded — reviewer, period covered, sources examined, whether anomalies were found, and follow-up actions — in an append-only register that cannot be edited or deleted after the fact. Anomalous activity found during a review is escalated under our incident-response policy, which is reviewed at least every six months.

8. Third-party and service access

Access granted to third-party services and integrations is limited to what is necessary for the service to function. Carrier, payment, and platform integrations operate under scoped credentials with the minimum required privileges. Privileged service credentials are used only server-side and are never exposed to the browser. See our Privacy Policy and Terms of Service for related commitments.

9. Policy owner and review

This Policy is owned by MyShipPilot LLC. It is effective as of the date shown above and is reviewed at least annually and following material changes to our security posture or systems. We may update this Policy from time to time; material changes are reflected by updating the "Effective date" shown above.

10. Contact

Questions about this Policy may be directed to privacy@myshippilot.com or security@myshippilot.com. For security vulnerability reports, email security@myshippilot.com.

This Policy is a governance statement and does not modify our Terms of Service. In the event of a conflict, the Terms of Service control with respect to your use of the Service.