Security
Enterprise-grade access, built in
From multi-factor sign-in to an immutable audit trail, FleetConnect gives IT and security teams the controls they expect.
Access & governance
Control who sees what
Single sign-on — coming soon
Enterprise SSO via SAML 2.0 and OpenID Connect, configured per organisation.
Multi-factor authentication
MFA with authenticator apps (TOTP) and single-use recovery codes. Mandatory for admins.
Granular roles & scoping
Role-based access from a catalogue of named permissions — scope users to specific vehicle groups and regions.
Immutable audit log
Every security and data-change event recorded append-only — actor, action, target, time, source IP — retained as your policy requires.
Safeguards
How we protect your data
The technical and organisational measures described in our Privacy Notice. No system is perfectly secure, but these are the main ones.
- Encryption in transit
- Connections to our website, apps and APIs are encrypted with TLS (HTTPS).
- Encryption at rest
- Uploaded documents are encrypted with managed keys, backups are encrypted, and authenticator-app secrets are encrypted in our database.
- Password protection
- Passwords are kept only as Argon2id hashes — never in a form that can be reversed — and earlier ones are kept the same way so they cannot be reused.
- Multi-factor authentication
- Authenticator-app (TOTP) codes, with hashed single-use recovery codes. Mandatory for administrators; organisations can require it for everyone.
- Session limits
- Access tokens expire after 60 minutes, and every session ends within 90 days.
- Access control
- Role-based permissions, which can limit a user to particular vehicles.
- Customer separation
- Each customer’s data is kept apart from every other customer’s, enforced in the database itself.
- Audit trail
- Security and data-change events are recorded append-only — who acted and on whose behalf, what they did, when, and from which IP address.
- Recorded support access
- When our support team needs to see a customer’s workspace, they use a dedicated support-access tool, and every session is recorded.
Organisational measures
- Need-to-know access
- Our staff access personal information only where their role requires it.
- Supplier safeguards
- We use providers that commit to protecting data, and bind them to that by contract.
- Incident response
- We investigate suspected breaches promptly, and notify the people affected and regulators where the law requires.
Where your data lives. Our platform — its database, files and backups — is hosted by Amazon Web Services in Mumbai, India. Our website and web apps are served by Google Firebase.
Built to align with GDPR, SOC 2 and ISO 27001 controls.
Your data, your rights
Privacy documents
Privacy Notice
What we collect, why, who we share it with, how long we keep it, and your rights.
Learn more →Global Privacy Notice
Privacy by region, who is responsible for your information, and how to make a request.
Learn more →Delete your account
How to ask us to delete your account and data, and what happens next.
Learn more →Get your first vehicle on the map
Sign up online in a few steps — your workspace is provisioned automatically, and there’s no sales call required.