Skip to content

Security

Enterprise-grade access, built in

From multi-factor sign-in to an immutable audit trail, FleetConnect gives IT and security teams the controls they expect.

Access & governance

Control who sees what

Single sign-on — coming soon

Enterprise SSO via SAML 2.0 and OpenID Connect, configured per organisation.

Multi-factor authentication

MFA with authenticator apps (TOTP) and single-use recovery codes. Mandatory for admins.

Granular roles & scoping

Role-based access from a catalogue of named permissions — scope users to specific vehicle groups and regions.

Immutable audit log

Every security and data-change event recorded append-only — actor, action, target, time, source IP — retained as your policy requires.

Safeguards

How we protect your data

The technical and organisational measures described in our Privacy Notice. No system is perfectly secure, but these are the main ones.

Encryption in transit
Connections to our website, apps and APIs are encrypted with TLS (HTTPS).
Encryption at rest
Uploaded documents are encrypted with managed keys, backups are encrypted, and authenticator-app secrets are encrypted in our database.
Password protection
Passwords are kept only as Argon2id hashes — never in a form that can be reversed — and earlier ones are kept the same way so they cannot be reused.
Multi-factor authentication
Authenticator-app (TOTP) codes, with hashed single-use recovery codes. Mandatory for administrators; organisations can require it for everyone.
Session limits
Access tokens expire after 60 minutes, and every session ends within 90 days.
Access control
Role-based permissions, which can limit a user to particular vehicles.
Customer separation
Each customer’s data is kept apart from every other customer’s, enforced in the database itself.
Audit trail
Security and data-change events are recorded append-only — who acted and on whose behalf, what they did, when, and from which IP address.
Recorded support access
When our support team needs to see a customer’s workspace, they use a dedicated support-access tool, and every session is recorded.

Organisational measures

Need-to-know access
Our staff access personal information only where their role requires it.
Supplier safeguards
We use providers that commit to protecting data, and bind them to that by contract.
Incident response
We investigate suspected breaches promptly, and notify the people affected and regulators where the law requires.

Where your data lives. Our platform — its database, files and backups — is hosted by Amazon Web Services in Mumbai, India. Our website and web apps are served by Google Firebase.

Built to align with GDPR, SOC 2 and ISO 27001 controls.

Get your first vehicle on the map

Sign up online in a few steps — your workspace is provisioned automatically, and there’s no sales call required.