Sign in
Trade Integrity & CryptographyRef: CORP-LEGAL-2026

Security & Compliance

The technical architecture, cryptographic verification standards, and institutional data pipelines ensuring the integrity of every trade record, facility dossier, and proforma packet on CorpiFind.

Last Updated:22 September 2026
Effective Date:22 September 2026
Jurisdiction:Türkiye & EU/EEA

1. Security Principles & Architecture

International agricultural and aquaculture procurement involves multi-thousand-ton shipments, complex phytosanitary clearances, and millions of Euros in Letter of Credit (L/C) exposure. In international food commodity supply chains, a falsified veterinary certificate, mismatched facility approval code, or altered proforma quantity can result in customs detention, cargo spoilage, and substantial financial losses.

CorpiFind operates on an evidence-first security model. Every claim made by our platform is anchored in verifiable institutional records, cryptographic hashing, and defense-in-depth software controls.

2. Cryptographic Document Notarization

When a buyer and supplier generate a proforma invoice, export dossier, or bilateral commercial terms packet within CorpiFind:

Deterministic SHA-256 Digesting:

The canonical representation of the document (including commodities, exact calibers, named Incoterms port, total value, buyer and seller identifiers, and timestamp) is serialized into a standard cryptographic SHA-256 hash.

Example Digest: 4a2a19b88e14675765942484437d8da6b42ddb199042ab7f29f041d8e1f5743c

Any party — including customs brokers, issuing banks, or port authorities — can independently verify the authenticity and tamper-free status of the document at corpifind.com/verify. Even a single character alteration in quantity or HS/GTİP tariff classification will invalidate the cryptographic hash.

3. Official Data Sources

CorpiFind does not currently verify suppliers against ministry or EU registries. Official datasets are loaded only from sources whose licence and origin have been approved; where a page has no official data loaded yet, it says so plainly, and figures that cannot be sourced are not published.

4. Encryption & Infrastructure Security

Transport Layer Security:All web and API traffic is encrypted over HTTPS.
Credential Storage:Passwords are stored only as bcrypt hashes. Staff two-step verification secrets are encrypted in the database with AES-256-GCM; only hashes of recovery codes are kept.
Network Rate Limiting:Sign-in endpoints allow 10 requests a minute and the general API 300; repeated failed sign-ins lock the account for a while.
Input Sanitization & DTOs:Request bodies are validated with class-validator schemas, and database queries are parameterised.

5. Identity, Access & Security Log

Customer accounts carry one of four trade roles: buyer, supplier, customs_broker, and freight_forwarder. The administration console runs on a separate domain with separate staff accounts; every staff sign-in requires two-step verification (TOTP), and staff permissions are granted one by one through roles.

Sessions are governed by rotating refresh tokens hashed at rest in the database. If a token reuse attempt is detected (such as if an adversary steals an expired token), our backend invalidates the entire session family immediately, safeguarding enterprise accounts against session hijacking.

Sign-ins, password and account changes, and staff actions are written with the IP address and browser details to a security log that cannot be edited. Entries are kept for 24 months, after which the IP address, browser details and identifiers are removed.

6. Responsible Vulnerability Disclosure

CorpiFind welcomes reports from independent security researchers, maritime logistics partners, and customs technology experts. If you believe you have discovered a vulnerability or trade data discrepancy:

VARS Su Ürünleri İth. İhr. San. ve Tic. Ltd. Şti. — Security & Compliance Desk

Email: [email protected] / [email protected]

Corporate Office: İsmet Kaptan Mah., Şair Eşref Blv. No:6 D:304/B, Konak, İzmir, 35210, Türkiye

PGP Key: Available upon request

Please include detailed steps to reproduce, affected endpoints, and avoid destructive actions or accessing third-party commercial data. We acknowledge all disclosures within 24 hours and provide rapid remediation.