Security
Security and privacy by default
Tenant isolation
Every customer-owned record carries a tenant identifier and is protected by PostgreSQL row-level security. The application connects with a role that cannot bypass these policies, and automated tests prove that one tenant cannot read or write another's data.
Encryption
- TLS 1.2+ for all traffic; HSTS on our web properties.
- Encryption at rest with cloud KMS; documents stored with server-side KMS encryption.
- Field-level AES-256-GCM encryption for direct identifiers such as CDL numbers, with key rotation.
- Passwords hashed with scrypt; sessions are random tokens stored only as hashes.
Access control & audit
- Role-based access, deny-by-default, with separation between dispatch and billing.
- MVR and medical data restricted to safety roles, with every disclosure logged.
- An append-only, hash-chained audit log of every change that customers can verify.
Payments
Card payments are processed by Stripe on Stripe-hosted pages; card data never touches our servers.
Data residency
Customer data is hosted in United States cloud regions only.
Compliance program
Our controls are designed against SOC 2 and the NIST Cybersecurity Framework. We will publish attestation status here once an independent audit is complete — we do not claim certifications we do not hold.
Report a vulnerability
Email security@haulsky.com. We welcome good-faith research and will respond promptly.