Trust
How your documents and data are handled
Borderless holds import records because federal regulation requires it. This page states what we hold, how long it stays, who is allowed to see it, and what runs on this website.
Scope
What we hold, and why we have to
An entry is built out of your commercial paperwork. To file one, Borderless receives and stores the documents listed here.
Every one of them is part of the entry record.19 CFR part 163 makes the broker responsible for the records behind each filing, and CBP can require them to be produced. Retention here is a legal duty rather than a product decision, and that shapes every answer below.
- Commercial invoices
- Value, currency, terms of sale and the parties to the transaction.
- Packing lists
- Piece counts, weights, marks and numbers.
- Bills of lading and arrival notices
- Carrier, vessel or flight, container numbers and routing.
- Powers of attorney
- The signed authority that lets us act as your agent before CBP.
- Importer registration (CBP Form 5106)
- Legal name, address and importer number, usually an EIN.
- Entry and ISF transmissions
- What we sent to CBP on your behalf, and what CBP sent back.
Recordkeeping
Five years, set by regulation
The period
Entry records are kept for five years from the date of entry under19 CFR 163.4(a).19 CFR 111.23 requires a broker to keep them at a known place of business for the same period.
Powers of attorney
A power of attorney runs on its own clock. It is kept while it is in force, and a revoked one is kept for five years after the revocation (19 CFR 163.4(b)(1)).
When an account closes
Closing an account does not start a deletion. The duty attaches to the record itself and survives the relationship, so filings already made stay for the balance of their five years under the same confidentiality rule.
It follows that Borderless cannot honour a request to erase your entry documents inside that window. A broker who deletes them on request is the broker who cannot answer CBP two years later, and the licence is what pays for that.
Your own file is a different matter. Ask for a copy at any time and you get one.
An inquiry that never became an engagement is not an entry record. Emailhello@borderlesschb.us and we will remove it.
Confidentiality
Your records are confidential by regulation
19 CFR 111.24 binds every licensed customs broker. The contents of a client's records, and information connected with them, may not be disclosed to anyone other than the client, the surety on a particular entry, or a representative of CBP or another federal agency acting under law. Your written authorisation is what widens that circle.
Two things follow, and both are worth stating plainly. Borderless does not sell client data or share it for marketing. A request for your records from anyone but you is refused unless it arrives with your written authorisation or as legal process.
The rule is enforced by the regulator that issued the licence, so a breach of it is a matter for CBP rather than a matter of contract alone. Most vendors handling the same documents carry no equivalent duty.
Access
Who can get into your account
Everyone signs in as themselves. Borderless does not issue shared logins, because the record of who filed what has to name a person.
Two roles. An Admin sees invoices, statements and your rates. A User does the filing work and everything else.
You control the list. Adding and removing people is self-serve in Settings, so access ends the moment you end it.
Outside addresses wait for approval.Sign-ins are meant for your own staff, so an address outside your company's email domain does not work until we approve it. That stops an outside address being added quietly to an importer's account.
This website
Everything on borderless.us that reports anything, anywhere
Three scripts run in your browser on this site. These are all of them.
1. Attribution, in your tab
A small script keeps the page you landed on, any campaign parameters in the URL, and the referring address in sessionStorage. It stays in that tab. It reaches us only if you submit the contact form, so the inquiry can say which page produced it. Closing the tab clears it.
2. Vercel Web Analytics
Page-view counting from our host, served from this domain at/_vercel/insights/script.js. It reports which pages get read.
3. A first-party beacon
Pages under /rulings, /ask,/classify-my-product and/binding-ruling send one request per view carrying two values: the path, and the hostname of the site that referred you. It sets no cookie. Your address and user agent are not part of it, and no other page sends it.
What the forms do
- The contact form posts to our own endpoint, which stores the inquiry and emails a copy to us. The database key it uses is server-side and never reaches the browser.
- A question to a broker goes to the Borderless platform, the same system that runs the client portal. Your IP address stays inside the website function. The platform receives a hashed token in its place.
- Usage counters for the tariff simulator and the rulings search store one sha256 hash per counter, computed with a server-side secret. Raw addresses never enter that table, and row-level security is on with no policies, so only the service key can read it.
What is not here
- No advertising or social trackers, and no session recording.
- Fonts are bundled into the site and served from this domain, so loading a page contacts no font CDN.
- Nothing sets a cookie until you use a metered tool. Those cookies are signed, HttpOnly and Secure, and they carry a random id rather than anything about you.
Providers that handle data for this website
Each row names a file in our own source that proves it. This list covers borderless.us. It is maintained by hand, and a change to it changes this page.
- Vercel
- Hosting, the serverless functions behind the forms, and Web Analytics.
- astro.config.mjs
- Supabase
- The database holding contact inquiries and the tool usage counters.
- api/lead.ts
- Resend
- Delivery of transactional email, including the alert that carries your inquiry to us.
- api/lead.ts
- USITC
- Queried live when you search a tariff code here. The search term goes to hts.usitc.gov, and nothing about you goes with it.
- lib/hts.ts
Disclosure
Reporting a vulnerability
Send it tohello@borderlesschb.us. The same address is published at/.well-known/security.txt in the format RFC 9116 defines, so a researcher or a scanner finds it without asking.
Please test against your own account and your own data. Automated load and scanning tools are not welcome here, because importers have cargo moving against clocks that a degraded service will blow. Borderless runs no paid bounty programme.
Put this in the report
- The URL or endpoint involved.
- What you did, in enough detail for us to repeat it.
- What you were able to see or change that you should not have been.
- The date and time, with the timezone, so we can find it in the logs.
- How you want to be credited, if at all.
Scope of this page
This page names only what can be shown to be true today. Where a control is not named here, read it as not claimed, and ask us. A vendor questionnaire gets answered in writing against your own form rather than with a link to this page. See also ourprivacy policyand terms of use.
Last reviewed: September 9, 2026.
Running a vendor review?
Send the questionnaire and the security clauses in your contract. Borderless answers them in writing.