Company
Security at NesoTMS
NesoTMS connects to your NetSuite account and to your carrier accounts, so it holds keys that matter. This page lists what NesoTMS does to protect them, where your data lives and what it does not promise. Everything here describes how the product is built and run today.
Last updated
What NesoTMS holds for your company
NesoTMS keeps what it needs to rate, buy and record shipments, and nothing more.
- Your NetSuite connection: the account, the address of the NesoTMS script in your NetSuite account and the token keys you paste in. After you save them they are never shown again.
- Your carrier accounts: the credentials each carrier gave you, and the settings you choose on the Carriers page.
- Shipments: every label NesoTMS buys, with the order details it was bought for (addresses, packages, tracking number, cost), the label files, carrier documents such as commercial invoices, and the status updates carriers report.
- Quick ship data: the manual orders and the address book your team types or imports.
- Setup choices: which NetSuite records to import and how fields map, your onboarding answers, saved reports and the printing computers you approved.
- Billing: your plan, and the Stripe customer and subscription it belongs to. Card numbers are entered on Stripe's pages and never reach NesoTMS.
- Accounts: who signs in to your company and whether they are an admin or a member. Clerk handles accounts and sign-in.
Keys and credentials are sealed and write-only
- Before anything is saved, each NetSuite key and carrier credential is encrypted with AES-256-GCM.
- Each encrypted value is bound to your company and to the field it belongs to, so a value copied into another company's record cannot be opened.
- The key that opens them is part of the engine server's private configuration, apart from the database. The database holds only encrypted values.
- Keys are write-only. Neither the dashboard nor the engine ever sends one back to a browser, and keys are kept out of logs and error messages.
- The engine opens a key in memory only to call NetSuite or the carrier for your company.
- In the hosted service the dashboard itself stores no company's keys.
Every company is isolated
- A company is a Clerk organization. The dashboard takes the company from your verified sign-in on the server, never from anything the browser sends, and names it to the engine on every request.
- The dashboard asks the engine which company it is serving before a company's first request, about once a minute after that and before every purchase, and it stops if the answer does not match.
- The engine accepts requests only with a long private token that lives on the servers, and it rejects any company, account or token field a browser tries to send.
- In the engine's own database, every table that holds company data uses forced row-level security. A query sees only the rows of the company named in its own transaction, and a connection that names no company sees none.
- Shipment history in Supabase follows the same rule, and label files sit in a private storage bucket that browsers have no way to open.
- Onboarding answers and saved reports are protected by row-level security that reads your company and role from your signed-in session.
- Automated tests check that one company cannot read or change another company's purchase ledger, carrier accounts, shipments, labels or NetSuite settings.
Who can do what
NesoTMS has two roles, admin and member. The person who creates a company is its first admin.
| Action | Admin | Member |
|---|---|---|
| Rate, buy and print labels | Yes | Yes |
| Void a label | Yes | Yes (recording a FedEx Freight cancellation needs an admin) |
| Use Quick ship, Shipments and Reports | Yes | Yes |
| Add, change, remove or test carrier accounts | Yes | No |
| Connect NetSuite and change import settings | Yes | No (view only) |
| Approve, rename or remove a printing computer, and set print rules | Yes | No (view only) |
| Invite or remove people | Yes | No |
| Manage billing and the plan | Yes | No |
The server checks the role on every change. Hiding a button in the page is never the only check.
A label is bought once
- Before a purchase reaches a carrier, NesoTMS records it in a ledger under a one-time key. Repeating the same request returns the first result, and a changed request under the same key is refused.
- If a carrier does not answer clearly (a timeout, or a reply that cannot be read), the purchase is kept as unconfirmed and guarded. NesoTMS never retries a purchase on its own, and it tells you instead of guessing.
- A void uses the carrier account and environment the label was bought with.
- The engine does not delete shipment records. A voided label is marked voided and stays on record.
Connections are encrypted
- The website and the dashboard are served over HTTPS.
- The dashboard talks to the engine only over HTTPS. The engine's address is checked, and plain HTTP is refused except on a developer's own computer. The engine's web server gets and renews its certificate by itself.
- Requests from the dashboard's server to the engine carry a long private token. The token never reaches a browser.
- The engine reaches NetSuite only at your account's own address on restlets.api.netsuite.com, which is checked when you save it.
- The engine's connection to the shipment database in Supabase must use verified TLS. The engine refuses to start otherwise.
Sign-in, the server and the browser
- Sign-in is passwordless: Clerk emails you a six-digit code, so there is no password to reuse or leak.
- The engine runs as an unprivileged service with system-level sandboxing: no extra privileges, a read-only file system, restricted system calls, and nothing written to disk. It and its database listen only on the server's local interface, behind a web server that handles HTTPS.
- The engine's database login is an ordinary one. It cannot bypass row-level security, and the engine refuses to start if it could.
- A browser can ask the dashboard only for a fixed list of commands, each with a fixed list of fields. Changes must come from the same site, and the browser is told not to cache engine responses.
- Every page is sent with headers that stop other sites from framing it, stop content-type guessing, shorten the referrer and switch off camera, microphone and location.
- Logs record what ran (the command, the company ID, the result and the timing), never names, addresses, tracking numbers, tokens, keys or request bodies. The web server's access log hides the authorization header.
- A packing computer can print only after an admin approves it. Each computer has its own key, and an admin can remove it at any time. Label files sent to it are held in memory for ten minutes, and a voided label is never delivered.
- Payments go through Stripe Checkout and its customer portal. Calls from Stripe are checked against Stripe's signature before they change anything.
Where your data lives
| What | Where | Notes |
|---|---|---|
| The website and the dashboard's server code | Vercel | Stores no company's keys. |
| Accounts, companies, members and roles | Clerk | Passwordless sign-in with an emailed code. |
| NetSuite keys and carrier credentials, the purchase ledger, Quick ship orders, the address book, billing state and print stations | NesoTMS's own engine server and its PostgreSQL database | Credentials are encrypted. Each company's rows are separated by row-level security. |
| Shipment history, label files and carrier documents | Supabase database and a private storage bucket | Reached only by the engine's own database login, never by a browser. |
| Onboarding answers and saved reports | Supabase database | Row-level security reads your company and role from your session. |
| Card payments and invoices | Stripe | Card details are entered on Stripe's pages. |
| Orders and fulfillments | Your NetSuite account | NesoTMS reads them and writes back tracking, package details, cost and ship status. |
To rate or buy a label, NesoTMS also sends the shipment details a carrier needs to the carrier accounts you connect.
What this page does not promise
- It is a description of how NesoTMS is built and run, not an audit report, and it makes no compliance claims.
- It gives no uptime or recovery-time figures.
- Like any hosted service, NesoTMS's own administrators who hold the hosting and database accounts can technically reach stored shipment data. Credentials stay encrypted in the database, and the key that opens them is held separately on the engine server.
- What NesoTMS can do inside NetSuite is limited by the NetSuite role you give its token. You can revoke the token in NetSuite at any time.
- UPS, FedEx, USPS and NetSuite keep their own security. This page covers NesoTMS only.
Report a security issue
Email info@nesotms.com with what you found and how to reproduce it. Please don't access, change or keep another company's data while you look.
Security questions
Does NesoTMS store my NetSuite password?
- No. NesoTMS connects to NetSuite with token keys that you create in NetSuite and tie to a role you choose. You can revoke the token in NetSuite at any time. The keys are encrypted and never shown again.
Can another company see my shipments or carrier accounts?
- Not through NesoTMS. Each company's data is separated by company in the dashboard, in the engine and in both databases, and the databases themselves refuse rows that belong to another company.
Can a team member change our carrier accounts?
- No. Only admins can add, change, remove or test carrier accounts and change NetSuite settings. Members can rate, buy and void labels.
Does NesoTMS store credit card numbers?
- No. You enter card details on Stripe's pages. NesoTMS keeps your plan and the Stripe customer and subscription it belongs to.
Can a label be bought twice by mistake?
- No. Every purchase is recorded before it reaches the carrier, a repeated request returns the first result, and NesoTMS never retries a purchase on its own. If the outcome is unclear, the order stays guarded until it is settled.
Where is my data stored?
- Accounts are in Clerk. Keys, the purchase ledger, Quick ship data and billing state are on NesoTMS's engine server. Shipment history, label files, onboarding answers and saved reports are in Supabase. Payments are in Stripe. Your orders stay in your NetSuite account.
Related pages
- PricingBasic $99/month or Advanced $499/month, with every shipping feature in both plans.
- NetSuite shipping integration: reads and writesNesoTMS reads Picked and Packed item fulfillments or open sales orders from NetSuite, buys the label and writes tracking, weights, sizes, cost and status back.
- Carrier coverageUPS, FedEx, USPS and FedEx Freight side by side: what works today and what is coming.
- ChangelogWhat changed in NesoTMS, newest first: new carriers, Quick ship, reports, printing, Canada shipping, billing and speed-ups, with the date each one shipped.