Security and Governance for Logistics AI

Written for CISOs, data-protection officers and customs compliance teams. Confidential data stays in your own infrastructure, every request is checked and logged, and a person approves every output.

The Data Boundary

Stays in Your Account

  • Shipment and TMS dataBookings, milestones, exceptions and documents.
  • Rates and contractsRate cards, quotes, tenders, SLAs and carrier terms.
  • Customs filesInvoices, packing lists and declaration history.
  • Telematics and videoVehicle data, temperature logs and camera footage.
  • Prompts, outputs and logsEverything your teams ask and every answer.

May Leave, Under Your Control

  • Operational health metricsCPU, memory, uptime and error rates, which you can inspect or switch off.
  • Public-only managed AI tasksPort notices, weather, tariff news and public regulation, sent to Claude, GPT or Grok under a monthly cap.
  • Nothing elseManaged AI can be switched off entirely, per workflow or per client.

Regulations Mapped to Controls

How Ancoravia is designed to support the frameworks logistics companies work under.

FrameworkWhat it asks forAncoravia controls
GDPRPersonal data in shipments, emails and telematicsProcessing in your own account; role-based access; retention you control; DPIA documentation; no facial recognition
NIS2Security of transport and logistics operatorsIsolated deployment; security patching; logging and monitoring; incident support and documentation
EU AI ActTransparency, oversight and record-keepingHuman approval on every output; full audit trail; intended-use documentation; evaluation records
Union Customs Code and AEOAccuracy and control of customs processesBroker approval before filing; source-cited suggestions; logged decisions for audit
ISO 27001Information security managementAccess control, change management, staged releases and evidence for your ISMS
Customer contractsData-protection and confidentiality clausesPer-client separation; opt-outs per client; exportable audit logs

Ancoravia is designed to support these frameworks. It does not make your organisation compliant on its own: compliance depends on how you configure and use the platform, and on your own policies and processes.

Built-In Controls

Policy Check

Every request is checked for confidential data before any model sees it. When in doubt, it stays private.

Role-Based Access

Planners, brokers, warehouse teams and sales see only what their role allows, with second approval where your SOP requires it.

Audit Trail

Every request, source, route and approver is logged in your account and exportable for audits.

Human Oversight

Nothing is sent to customers or carriers, filed with customs or changed in your systems automatically.

Encryption

Data encrypted in transit and at rest with keys managed in your own cloud account.

Evaluation Gates

Models and configurations go live only when they meet your experts’ standard, with one-step rollback.

Security Questions

For IT, security and compliance teams.

What exactly leaves our account?

Shipment, rate, customer, customs and telematics data never leaves, including prompts, outputs, documents and logs. Only operational health metrics leave, and you can inspect or switch them off. Managed AI receives only the public sources and public-only tasks you route to it, under a monthly cap.

Can Xenium Cloud Technologies staff see our data?

No. We operate the platform through deployment and monitoring tooling that has no access to your data, prompts or outputs. Any break-glass access for support requires your explicit approval and is logged.

Where is our data processed?

In your own cloud account, private cloud, data centre or site-edge servers, in the region you choose. For EU customers this can be kept entirely within the EU.

Is Ancoravia compliant with the EU AI Act?

Ancoravia is designed to support your obligations under the EU AI Act, with logging, human oversight, documentation and evaluation records. Compliance depends on how your organisation defines and uses each workflow, which is why we document intended use together with you.

How are models evaluated before going live?

Your experts rate answers on real cases during the pilot. A new model or configuration goes live only when it meets the thresholds you set, and every release can be rolled back in one step.

Request the Security Overview

We share the full architecture, data-flow and control documentation with your security and compliance teams before any pilot starts.