Enterprise-Grade Security

Security &
Compliance

Your data security is our top priority. Learn about the measures we take to protect your transportation management information.

Comprehensive Security Framework

We implement multiple layers of security to protect your data, ensure compliance, and maintain the highest standards of trust.

Implemented

End-to-End Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.

In progress

Multi-Factor Authentication

Authenticator-app (TOTP) two-factor authentication for carrier and admin accounts.

Implemented

Access Controls

Role-based permissions ensure users only access data they're authorized to see.

Implemented

Infrastructure Security

Hosted on managed cloud infrastructure with automated daily backups and point-in-time recovery.

Implemented

Automated Security Gates

Every API route and database migration is checked against our security rules before it can ship.

Active

Incident Response

Automated detection of privilege escalation and cross-account access, with immediate account suspension and a tamper-resistant audit log.

Data Protection & Privacy

Encryption Everywhere

All data is encrypted using industry-standard AES-256 encryption at rest and TLS 1.3 in transit.

Data Minimization

We only collect and store data necessary for providing our transportation management services.

Regular Backups

Automated daily backups with point-in-time recovery capabilities ensure your data is never lost.

Data Residency

All data is stored in secure data centers within the United States, complying with federal regulations.

Defense in depth
AES-256 at rest
Encrypted storage
TLS 1.3 in transit
Encrypted transport
Row-level security
Per-account isolation
US data centers
Daily backups + PITR

Compliance Status

Where we stand against the regulations and security frameworks that matter for carriers. We report progress honestly, including the work still in flight.

SOC 2 Type II

In progress

Readiness work underway across security and confidentiality controls; independent audit not yet complete

FMCSA Clearinghouse

Implemented

Integrated for query and reporting under 49 CFR Part 382 Subpart G

DOT Recordkeeping

Implemented

Driver qualification, HOS and DVIR records retained per 49 CFR Parts 391, 395 and 396

Data Privacy

In progress

Row-level access control, encrypted transport, and documented retention and deletion

Infrastructure & Network Security

Built on enterprise-grade infrastructure with multiple layers of protection.

Cloud Infrastructure

  • Hosted on managed AWS-backed infrastructure
  • Auto-scaling and load balancing
  • DDoS protection and WAF filtering
  • Geographic redundancy and failover

Monitoring & Response

  • 24/7 security monitoring and alerting
  • Automated threat detection and response
  • Incident response team on standby
  • Regular vulnerability assessments

Security Best Practices for Users

Help us keep your account secure by following these recommendations.

Account Security

  • Use strong, unique passwords

    Create complex passwords with at least 12 characters

  • Enable two-factor authentication

    Add an extra layer of security to your account

  • Keep your information updated

    Ensure contact information is current for security alerts

Safe Usage

  • Log out from shared devices

    Always sign out when using public computers

  • Be cautious with email links

    Verify sender before clicking links or downloading files

  • Report suspicious activity

    Contact us immediately if you notice unusual account activity

Security Questions or Concerns?

Our security team is here to help. Report vulnerabilities or get answers to your security questions.
For security vulnerabilities, please email support@tl1inc.com