Security
Trust is a set
of controls.
What protects carrier data and who can act on it, described as it is built. Where something is not done yet, this page says so.
Carrier A
- Trucks
- Loads
- Rules
- Documents
Carrier B
- Trucks
- Loads
- Rules
- Documents
Row-level security · in the database
- Cross-tenant probe
- about 36 attempts · 0 leaks
- Audit
- append-only · actor · time · outcome
- Safe mode
- one switch stops new autonomous work
01Data
Separated at the database.
- Tenant isolation
- Each carrier’s data is separated with PostgreSQL row-level security. The application runs as a database role that cannot bypass it.
- Tested
- A cross-tenant probe signs up two carriers and makes about 36 attempts to read or change the other’s records. It finds no leaks, including with the application check deliberately broken.
- Passwords
- Stored as scrypt hashes. The password itself is never stored.
- Sessions
- Opaque tokens stored only as digests, with idle and absolute expiry.
- Reset links
- Single use, expiring, and all sessions end when a password is reset.
02Authority
Who can act, and on what.
- Roles
- Seven roles with specific capabilities. Tenancy is checked before anything else.
- Approvals
- Outside your rules, a person approves. A decline is a hard stop.
- Audit
- Material actions are recorded with actor, time, inputs and outcome, append-only.
- Safe mode
- One switch stops new autonomous work across the account.
- Calls
- The voice agent says it is an AI assistant at the start of every call.
03Not yet
What we haven’t done.
- Certifications
- Dispatch has not completed SOC 2 or any independent security audit. This page will say so when it has.
- Pen test
- No third-party penetration test yet.
- Security inbox
- A published security contact is not in place yet.