Security built into every layer.
LastMile is built for operations that handle personal delivery data. Identity, access, audit and retention are part of the platform, not an add-on you configure later.
The posture you get, on day one
POPIA-ready
Personal data is collected for a clear purpose, kept only as long as it is needed, and can be exported or erased on request. The tooling for a data-subject request is built in.
Identity
Sign-in runs through Microsoft Entra ID. No passwords are stored in LastMile, so your own identity provider and its policies, including multi-factor, apply.
Access control
Role-based access, deny by default. Every page, action and endpoint checks a permission, so a person sees only what their role allows and nothing more.
Auditability
Sensitive actions are recorded as events with who, what and when. Nothing important changes without a record you can review later.
Hosting
Hosted on Azure and shipped as containers, so the same build runs anywhere Docker does and your data stays in the region you choose.
Data lifecycle
Records are kept for a defined period and then removed. Retention is explicit, not accidental, and a deletion request is handled from start to finish.
Want the detail?
We are happy to walk your security team through identity, access, audit and data handling on a call.
Book a security review