Useful tracking. Deliberate boundaries.

Shipment Lookup is structured so public visibility and private operational access are different paths.

Limited public view

Public tracking is designed around shipment status and delivery context, not complete customer or order data.

Authenticated business access

Private records are accessed through signed-in accounts and database policies tied to record ownership.

Server-side privilege

Privileged credentials belong on trusted infrastructure and should not be embedded in browser code or public links.

Public tracking is intentionally narrow.

A tracking page can show shipment identifiers, status, estimate, event history, carrier labels, and limited route context. It is not intended to expose customer email, phone, full address, payment information, reusable credentials, or internal business notes.

Private records use authenticated access.

The business console uses Supabase authentication and account-scoped database policies. Signed-in users can work with records owned by their account. A publishable application key identifies the project but does not replace the user's authenticated session or grant privileged access by itself.

Database policy boundary

Private rows are governed by ownership rules rather than being generally readable from the public client.

Rate-limited public lookup

Public lookup can use short-lived request counting to make automated enumeration harder.

Reduced response surface

The public endpoint returns only the fields needed for the customer-facing tracking experience.

Integration credentials should remain private.

Trusted integrations should keep service credentials, private tokens, and reusable secrets on server infrastructure. Public shipment identifiers and publishable project keys should never be treated as substitutes for privileged authentication.

Failure should not become false data.

When a connected source is unavailable, the correct behavior is to report a service failure rather than silently translating it into “no shipment found.” That distinction protects both customer trust and operational troubleshooting.

Security is also a product behavior.

The safest shipment page is not simply one with encrypted transport. It also exposes the minimum useful information, separates estimates from events, avoids credentials in URLs, and gives private business operations a different access path from public tracking.