Skip to main content
Security

Trust Center

How we protect your data

Every control below is in place today. We list what we actually run, not what we intend to run.

Application security

Mandatory code review

Every change goes through a pull request with a named module owner as reviewer.

Automated testing on every change

Backend, frontend and analysis-engine suites, with a coverage floor enforced on changed code.

Daily dependency scanning

Every dependency is checked against published advisories, including on days nothing changed.

Secret scanning

Every commit and merge is scanned before it can reach a deployed environment.

Software Bill of Materials

A CycloneDX inventory of every component, regenerated weekly and on every release.

Web application firewall

AWS managed rule sets — IP reputation, common attack patterns and known bad inputs — at the CDN edge.

Independent code security review

An external firm audited the platform codebase in June 2026. Findings were triaged by severity.

Coordinated vulnerability disclosure

A published policy, a dedicated inbox, and a commitment not to pursue good-faith researchers.

Your data

EU data residency

Tachograph records, driver identities and infringements are held in AWS eu-central-1, Frankfurt.

Encrypted at rest

Database storage and object storage are encrypted, including every backup snapshot.

Encrypted in transit

TLS on every endpoint. Plain HTTP is redirected, never served.

Daily backups

Automated snapshots with a seven-day point-in-time recovery window.

Retention you control

Records are removed automatically once the agreed retention period expires.

Encrypted integration credentials

Credentials for your telematics platforms are encrypted separately from the rest of the database.

Your data does not train AI models

No customer or driver data is used to train, fine-tune or evaluate a model. Test runs use synthetic data.

Infrastructure

Multiple availability zones

The production database runs across two zones and fails over automatically in about 30 seconds.

No public SSH

Administrative access runs through AWS Session Manager. There are no open SSH ports and no shared keys.

Least-privilege access

Named accounts per person, scoped roles, and self-service multi-factor authentication.

Automatic security patching

Managed services take minor-version security updates automatically.

Infrastructure as code

Every environment is defined in version control, and each change is reviewed as a plan before it applies.

Managed secrets

Credentials live in AWS Parameter Store and Secrets Manager, never in code or container images.

Detection and response

Threat detection

Amazon GuardDuty watches API activity, DNS, network flows, object storage events and database logins.

Malware protection

Storage volumes are scanned when a finding suggests they should be.

Audit logging

Multi-region CloudTrail with log-file validation, so tampering with the record is detectable.

Network flow logs

Every connection to and from the production network is recorded.

Error tracking and alarms

Application errors, performance traces and infrastructure alarms route to an on-call channel.

Incident response plan

A named commander, a declaration within 15 minutes, and a published post-mortem within five business days.

Disaster recovery plan

A four-hour recovery time objective and a 24-hour data loss tolerance, with a runbook per failure scenario.

Recovery drills

We rehearse a full database restore rather than assuming the backups work. Most recent drill: August 2026.

Public status page

Component-level status and 90-day uptime history, open to anyone.

In the product

Two-factor authentication

Available by request.

Role-based permissions

Access is scoped by role and by location, down to individual records.

Support sessions are marked

When our support team works inside your account, that activity is separated from your own users' data.

Keeping this current

Annual policy review

Every policy on this page is reviewed at least once a year, and whenever the platform materially changes.

30 days' notice on sub-processors

You hear about a new sub-processor before it starts processing, with a route to object in writing.

Aligned to the EU Cyber Resilience Act

Security by design, vulnerability handling and incident reporting follow Regulation (EU) 2024/2847.

Documents

Anything already published is linked here directly. Everything else we send on request via security@rs-roadsoft.com.