As a leading provider of technology solutions to businesses in the supply chain industry, FourKites has made data security for our customers and data providers a top priority. As the platform where AI agents resolve supply chain disruptions at scale, FourKites applies the same rigor to protecting customer data that we apply to moving it. This page summarizes our certifications, security controls, and vulnerability reporting program.
1. Security for an AI-Native Platform
FourKites processes data in real time, across millions of shipments, using AI agents that make autonomous decisions on behalf of our customers. The security of that data is foundational to everything we do.
Our AI agents process shipment events, carrier communications, and supply chain signals continuously. Every data point they act on is governed by the same security controls that protect all customer data on the platform.
FourKites' network intelligence — drawn from 1,600+ businesses — is used in aggregated, anonymized form only. Customer-specific data is never used to train third-party models.
Access to AI processing infrastructure follows the same least-privilege, MFA-enforced, and audit-logged controls as all other platform systems.
Our AI governance framework is described separately on our AI at FourKites page.
2. Certifications & Compliance
FourKites maintains the following internationally recognized certifications, each audited annually by an independent third party. Certification reports are available upon request under a Non-Disclosure Agreement by emailing infosec@fourkites.com.
ISO 27001 / 27017 / 27018
FourKites is certified under ISO 27001 (Information Security Management), ISO 27017 (Cloud Service Security), and ISO 27018 (Protection of Personally Identifiable Information in the Cloud). Together these certifications confirm that FourKites has implemented a comprehensive ISMS designed to protect customer data across cloud environments.
FourKites is SOC 2 Type II certified in accordance with the AICPA Trust Services Criteria. SOC 2 Type II evaluates both the design and operating effectiveness of security controls over a sustained audit period. FourKites undergoes this audit annually with an independent third-party auditor.
Note that the SOC2 and ISO 27001 standards consist of 300+ different controls that FourKites gets audited annually on by an independent third party.
Data Privacy Framework
FourKites, Inc. is self-certified under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce.
3. FourKites Security Program:
FourKites maintains a comprehensive Information Security Management System (ISMS) based on the ISO 27001 framework, applied across all platform components, including AI processing infrastructure, the carrier network, and customer-facing applications. For security reasons, we do not publish full control details publicly. We are happy to address further questions from your security team under a Non-Disclosure Agreement.
IT infrastructure – Protection from Data Loss, Corruption
All data in transit is encrypted using HTTPS with TLS 1.2 or higher. All data at rest is encrypted using AES-256.
Platform services are hosted in major commercial cloud environments with built-in redundancy, high availability, load balancing, and failover clustering
All databases are kept separate and dedicated to prevent corruption and overlap.
Infrastructure Security assessments are carried out regularly to report on vulnerabilities and notifications are set.
We have layers of logic that segregate Customer accounts from each other.
Customer data is regularly backed up and kept in separate locations (supported by the relevant cloud provider’s approach to redundancy and reliability).
We continuously monitor and record resource and data configurations for simple compliance auditing, security analysis, change management, and troubleshooting.
We continuously monitor and retain historical data of API's for governance, compliance, and risk auditing
We maintain confidential disaster recovery and business continuity processes.
Threat Detection & Vulnerability Management
We perform annual external security penetration tests on the Platform conducted by independent third-party security firms. The tests involve infrastructure-level server penetration testing and in-depth application vulnerability testing using OWASP Top 10 and SANS Top 25 industry standards.
Access Control
Access and identity management through individual user accounts with unique permissions, with multi-factor authentication (MFA) for privileged access.
Employee Checks, Training and Awareness:
All FourKites employees receive regular training on best security practices, including how to identify social engineering, phishing scams, DDoS attacks and hackers.
FourKites has established internal reporting mechanisms to appropriate teams.
FourKites employees on teams that have access to customer data (such as tech support and our engineers) undergo criminal history and background checks prior to employment as permitted in accordance with applicable laws.
4. Technical and Organizational Security Measures
FourKites' full Technical and Organizational Security Measures (TOMS) are incorporated by reference into our Data Processing Addendum and available here. Customers requiring a detailed review may contact infosec@fourkites.com.
5. Responsible Disclosures Program
FourKites maintains a Responsible Disclosure Program for legitimate security researchers. Full details, eligibility requirements, and submission guidelines are available here.
If you believe that you are seeing suspicious activity in relation to the FourKites Platform please email soc@fourkites.com.