Trust & Security

How we protect your fleet's data.

Routeon is built for operators who can't afford downtime or data loss. This page describes the controls, processes, and third parties we use to keep your workspace safe.

Uptime (90d)
99.98%
At rest
AES-256
In transit
TLS 1.3
Security monitoring
24/7

SOC 2 Type II in progress · PCI-DSS via Stripe · GDPR & CCPA aligned

Security posture Live

Controls you can verify

Encryption, access, and audit — not marketing claims.

  • Encryption
    At rest & in transit
  • SSO + MFA
    Okta, Google, SAML
  • Audit logs
    Every change tracked
  • Daily backups
    30-day point-in-time
Report a vulnerabilitysecurity@routeon.io →
In progress

SOC 2 Type II readiness

Routeon is actively working toward a SOC 2 Type II report covering Security, Availability, and Confidentiality. We have implemented the underlying technical controls (encryption, access control, logging, change management) and are partnering with a CPA firm on the formal observation window. Until the report is issued, we don't claim SOC 2 certification — but we'll share our security questionnaire, control matrix, and architecture overview on request.

Request our security package

Controls in place today

Every customer workspace gets these out of the box — there is no "premium" security tier.

Encryption in transit & at rest

All traffic served over TLS 1.2+. Customer data stored in a managed Postgres database with disk-level encryption at rest.

Authentication

Email + password with Have I Been Pwned screening, plus Google SSO. Sessions use short-lived JWTs with rotating refresh tokens.

Tenant isolation

Every customer table is protected by Postgres row-level security scoped to the workspace. Cross-tenant reads are denied at the database layer, not just the app.

Role-based access

Owner, Admin, Dispatcher, Accountant, Staff, and Driver roles enforced in both the UI and RLS. Drivers can only see their own assigned trips.

Backups

Daily automated backups of the production database with point-in-time recovery handled by our infrastructure provider.

Hardened hosting

Application runs on edge-grade serverless infrastructure with global DDoS protection in front of every request.

Audit trails

Sensitive events (contract sends, signatures, payments, platform-admin actions) are recorded in append-only audit logs visible to workspace owners.

Incident response

Defined runbook for triage, customer notification, and post-mortem. Material incidents are disclosed to affected workspaces within 72 hours.

Subprocessors

Routeon uses the following third parties to deliver the service. We will notify customers in-app before adding a new subprocessor that handles customer data.

ProviderPurposeRegion
Lovable Cloud (managed Postgres + Auth)Application database, authentication, file storageUS
CloudflareEdge runtime, CDN, DDoS protectionGlobal
StripePayment processingUS / EU
Google Maps PlatformGeocoding, routing, distance calculationGlobal
SamsaraOptional fleet telematics & HOS data (only when connected)US
Firebase Cloud MessagingDriver mobile push notificationsGlobal
Lovable transactional emailAuth and reservation emailsUS / EU

Data retention

Operational records (reservations, trips, invoices, driver logs) are retained for up to 7 years after a workspace is closed, to support DOT, financial, and audit recordkeeping requirements common to ground transportation. Customers can request earlier deletion of non-regulated personal data.

Privacy requests

Workspace owners can export and delete data directly from Settings. End-user access, correction, or deletion requests (GDPR / CCPA / Quebec Law 25) can be sent to the contact below and are processed within 30 days.

Report a vulnerability or security concern

We take security reports seriously and aim to respond within one business day. Please include reproduction steps and any relevant logs.

security@routeon.app