Security

Security and privacy by default

Tenant isolation

Every customer-owned record carries a tenant identifier and is protected by PostgreSQL row-level security. The application connects with a role that cannot bypass these policies, and automated tests prove that one tenant cannot read or write another's data.

Encryption

  • TLS 1.2+ for all traffic; HSTS on our web properties.
  • Encryption at rest with cloud KMS; documents stored with server-side KMS encryption.
  • Field-level AES-256-GCM encryption for direct identifiers such as CDL numbers, with key rotation.
  • Passwords hashed with scrypt; sessions are random tokens stored only as hashes.

Access control & audit

  • Role-based access, deny-by-default, with separation between dispatch and billing.
  • MVR and medical data restricted to safety roles, with every disclosure logged.
  • An append-only, hash-chained audit log of every change that customers can verify.

Payments

Card payments are processed by Stripe on Stripe-hosted pages; card data never touches our servers.

Data residency

Customer data is hosted in United States cloud regions only.

Compliance program

Our controls are designed against SOC 2 and the NIST Cybersecurity Framework. We will publish attestation status here once an independent audit is complete — we do not claim certifications we do not hold.

Report a vulnerability

Email security@haulsky.com. We welcome good-faith research and will respond promptly.