Your data, isolated and enforced.
You're trusting us with your tickets, your safety records, and your vendor spend. Here's exactly how that data is separated, protected, and kept yours: enforced at the database layer, not just promised in the interface.
Separated in the database itself.
Row-level security in Postgres, not an app filter. Another org's records cannot come back. We verify that on production.
Enforced where the data lives.
A driver cannot reach billing. An operator sees only their tickets. The rules hold even if someone skips the UI.
Encrypted in transit and at rest.
TLS on every connection. Encrypted Postgres. Files via short-lived signed links, not public buckets.
Photos and signatures, scoped to your org.
Ticket photos and signatures live in your org's space. Signed links only. No public URL.
Invite-only. No open front door.
No public self-signup. Accounts are provisioned. Only people you authorize get in.
A plan written down, not invented.
Severity, containment, customer notice, backup and restore. Written down so we follow the plan instead of inventing one under pressure.
We name the vendors.
Hosting, payments, monitoring, maps, email. Listed on the sub-processors page.
What we don't claim.
We don't hold certifications we haven't earned. No SOC 2 badge, no "bank-grade" marketing, no compliance logos we can't back. If a formal audit is worth pursuing as we grow, that's a decision we'll make with our customers, not a claim we'd fake. Everything on this page is how the product actually works today.
See how your data stays yours.
Book a demo and we'll walk the security model with you: the isolation, the access rules, the whole thing.
Book a demo