New here? Take the 4-step guided tour — live preview, packer bench, scenarios, and ERP portal.

Security summary

Version 2026.06.05-ecomm-1 · September 20, 2026

Service: maxpack.com.au — freight packing SaaS (parcel, container, ERP API).
Operator: Isbel Pty Ltd · ABN 20 138 742 720
Hosting: Australia (IONOS VPS) · Application path /var/www/maxpack
Contact: sales@maxpack.com.au

Authentication

  • Customer portal: session cookie (HttpOnly, Secure, SameSite=Lax), 8-hour idle timeout
  • ERP API: X-Api-Key per customer (bcrypt-hashed at rest); master key in server env
  • Packer display: signed station URL token
  • Optional email OTP for pilot accounts (MAXPACK_PORTAL_EMAIL_2FA)

Transport & headers

  • HTTPS with HSTS
  • X-Content-Type-Options, X-Frame-Options, Referrer-Policy
  • CSP (report-only) on production pages

Rate limiting & audit

  • Login and API rate limits per IP / API key
  • Append-only audit log: login, API auth, key rotation

Data

  • JSON files under data/ on application server (orders, packs, customer registry)
  • No payment card data processed
  • Deletion on written request within 30 days (see DPA)

Subprocessors

IONOS (hosting), Plausible (analytics, EU option available). See full list in procurement pack.

Download full pack Service status

See it on sample data — packer bench, 3D load, and minimum-cube optimizer. No signup.