Skip to main content
Security

Trust Center

At a glance

The four questions we are asked most often, answered before you have to ask them.

Frankfurt
EU data residency

All platform data is held in AWS eu-central-1. Vehicle track history sits in Azure West Europe.

7 days
Point-in-time recovery

Daily automated database snapshots across two availability zones, with a four-hour recovery objective.

2 days
Disclosure acknowledgement

We confirm every vulnerability report within two business days and resolve critical findings within 30.

2007
Serving fleet operators since

More than 2,500 fleet operators rely on Roadsoft for tachograph compliance.

Documents

Anything already published is linked here directly. Everything else we send on request via security@rs-roadsoft.com.

On request

Data Processing AgreementEmail
Information Security PolicyEmail
Security Incident Response PlanEmail
Disaster Recovery PlanEmail
Data Retention PolicyEmail
AI Assistant Data Handling PolicyEmail
Independent code security review, June 2026Email
Software Bill of MaterialsEmail
Security architecture diagramEmail

How we protect your data

Every control below is in place today. We list what we actually run, not what we intend to run.

Application security

Mandatory code review

Every change goes through a pull request with a named module owner as reviewer.

Automated testing on every change

Backend, frontend and analysis-engine suites, with a coverage floor enforced on changed code.

Daily dependency scanning

Every dependency is checked against published advisories, including on days nothing changed.

Secret scanning

Every commit and merge is scanned before it can reach a deployed environment.

Software Bill of Materials

A CycloneDX inventory of every component, regenerated weekly and on every release.

Web application firewall

AWS managed rule sets — IP reputation, common attack patterns and known bad inputs — at the CDN edge.

Independent code security review

An external firm audited the platform codebase in June 2026. Findings were triaged by severity.

Coordinated vulnerability disclosure

A published policy, a dedicated inbox, and a commitment not to pursue good-faith researchers.

Your data

EU data residency

Tachograph records, driver identities and infringements are held in AWS eu-central-1, Frankfurt.

Encrypted at rest

Database storage and object storage are encrypted, including every backup snapshot.

Encrypted in transit

TLS on every endpoint. Plain HTTP is redirected, never served.

Daily backups

Automated snapshots with a seven-day point-in-time recovery window.

Retention you control

Records are removed automatically once the agreed retention period expires.

Encrypted integration credentials

Credentials for your telematics platforms are encrypted separately from the rest of the database.

Your data does not train AI models

No customer or driver data is used to train, fine-tune or evaluate a model. Test runs use synthetic data.

Infrastructure

Multiple availability zones

The production database runs across two zones and fails over automatically in about 30 seconds.

No public SSH

Administrative access runs through AWS Session Manager. There are no open SSH ports and no shared keys.

Least-privilege access

Named accounts per person, scoped roles, and self-service multi-factor authentication.

Automatic security patching

Managed services take minor-version security updates automatically.

Infrastructure as code

Every environment is defined in version control, and each change is reviewed as a plan before it applies.

Managed secrets

Credentials live in AWS Parameter Store and Secrets Manager, never in code or container images.

Detection and response

Threat detection

Amazon GuardDuty watches API activity, DNS, network flows, object storage events and database logins.

Malware protection

Storage volumes are scanned when a finding suggests they should be.

Audit logging

Multi-region CloudTrail with log-file validation, so tampering with the record is detectable.

Network flow logs

Every connection to and from the production network is recorded.

Error tracking and alarms

Application errors, performance traces and infrastructure alarms route to an on-call channel.

Incident response plan

A named commander, a declaration within 15 minutes, and a published post-mortem within five business days.

Disaster recovery plan

A four-hour recovery time objective and a 24-hour data loss tolerance, with a runbook per failure scenario.

Recovery drills

We rehearse a full database restore rather than assuming the backups work. Most recent drill: August 2026.

Public status page

Component-level status and 90-day uptime history, open to anyone.

In the product

Two-factor authentication

Available on every account in the portal.

Single sign-on

Connect your own identity provider over OIDC and manage access where you already manage it.

Role-based permissions

Access is scoped by role and by location, down to individual records.

Audit log

User actions are recorded so you can see who changed what, and when.

Support sessions are marked

When our support team works inside your account, that activity is separated from your own users' data.

Keeping this current

Annual policy review

Every policy on this page is reviewed at least once a year, and whenever the platform materially changes.

30 days' notice on sub-processors

You hear about a new sub-processor before it starts processing, with a route to object in writing.

Aligned to the EU Cyber Resilience Act

Security by design, vulnerability handling and incident reporting follow Regulation (EU) 2024/2847.

Sub-processors

Roadsoft acts as processor on your behalf. These are the vendors we engage to deliver the platform, what each one is for, and where it processes data.

Sub-processor
Purpose
Processing region
Amazon Web Services
Hosting, storage and compute for the platform
EU — Frankfurt
Microsoft Azure
Vehicle position history and legacy file relay
EU — Netherlands
Twilio
WhatsApp and SMS delivery to drivers
EU — Ireland
Meta Platforms
WhatsApp Business message delivery, reached via Twilio
Outside EEA
Vonage
Voice and messaging to drivers
EU — Sweden
Mailgun
Transactional email and report delivery
EU
TachoSys
Fallback tachograph file decoding
EU
New Relic
Application performance monitoring
EU
Atlassian
Issue tracking and internal documentation
EU
Metabase
Internal business analytics
EU — Frankfurt
OpenAI
Language model behind the WhatsApp Assistant and summaries
Outside EEA
VAPI
Voice call orchestration
United States
Deepgram
Speech to text, inside the VAPI pipeline
United States
ElevenLabs
Text to speech, inside the VAPI pipeline
United States
Cartesia
Text to speech, inside the VAPI pipeline
United States
Transfers outside the EEA

Some of the vendors listed above process data outside the European Economic Area. Each is engaged under a data processing agreement incorporating the European Commission's Standard Contractual Clauses. Core platform data — tachograph files, driver records and infringements — is stored and processed in the EU; these vendors are involved only in the messaging, voice and assistant features.