Trust Center
At a glance
The four questions we are asked most often, answered before you have to ask them.
All platform data is held in AWS eu-central-1. Vehicle track history sits in Azure West Europe.
Daily automated database snapshots across two availability zones, with a four-hour recovery objective.
We confirm every vulnerability report within two business days and resolve critical findings within 30.
More than 2,500 fleet operators rely on Roadsoft for tachograph compliance.
Documents
Anything already published is linked here directly. Everything else we send on request via security@rs-roadsoft.com.
Published
Vulnerability Disclosure PolicyOpenPrivacy PolicyPDFTerms and ConditionsPDFSystem status and uptime historyLiveOn request
How we protect your data
Every control below is in place today. We list what we actually run, not what we intend to run.
Application security
Every change goes through a pull request with a named module owner as reviewer.
Backend, frontend and analysis-engine suites, with a coverage floor enforced on changed code.
Every dependency is checked against published advisories, including on days nothing changed.
Every commit and merge is scanned before it can reach a deployed environment.
A CycloneDX inventory of every component, regenerated weekly and on every release.
AWS managed rule sets — IP reputation, common attack patterns and known bad inputs — at the CDN edge.
An external firm audited the platform codebase in June 2026. Findings were triaged by severity.
A published policy, a dedicated inbox, and a commitment not to pursue good-faith researchers.
Your data
Tachograph records, driver identities and infringements are held in AWS eu-central-1, Frankfurt.
Database storage and object storage are encrypted, including every backup snapshot.
TLS on every endpoint. Plain HTTP is redirected, never served.
Automated snapshots with a seven-day point-in-time recovery window.
Records are removed automatically once the agreed retention period expires.
Credentials for your telematics platforms are encrypted separately from the rest of the database.
No customer or driver data is used to train, fine-tune or evaluate a model. Test runs use synthetic data.
Infrastructure
The production database runs across two zones and fails over automatically in about 30 seconds.
Administrative access runs through AWS Session Manager. There are no open SSH ports and no shared keys.
Named accounts per person, scoped roles, and self-service multi-factor authentication.
Managed services take minor-version security updates automatically.
Every environment is defined in version control, and each change is reviewed as a plan before it applies.
Credentials live in AWS Parameter Store and Secrets Manager, never in code or container images.
Detection and response
Amazon GuardDuty watches API activity, DNS, network flows, object storage events and database logins.
Storage volumes are scanned when a finding suggests they should be.
Multi-region CloudTrail with log-file validation, so tampering with the record is detectable.
Every connection to and from the production network is recorded.
Application errors, performance traces and infrastructure alarms route to an on-call channel.
A named commander, a declaration within 15 minutes, and a published post-mortem within five business days.
A four-hour recovery time objective and a 24-hour data loss tolerance, with a runbook per failure scenario.
We rehearse a full database restore rather than assuming the backups work. Most recent drill: August 2026.
Component-level status and 90-day uptime history, open to anyone.
In the product
Available on every account in the portal.
Connect your own identity provider over OIDC and manage access where you already manage it.
Access is scoped by role and by location, down to individual records.
User actions are recorded so you can see who changed what, and when.
When our support team works inside your account, that activity is separated from your own users' data.
Keeping this current
Every policy on this page is reviewed at least once a year, and whenever the platform materially changes.
You hear about a new sub-processor before it starts processing, with a route to object in writing.
Security by design, vulnerability handling and incident reporting follow Regulation (EU) 2024/2847.
Sub-processors
Roadsoft acts as processor on your behalf. These are the vendors we engage to deliver the platform, what each one is for, and where it processes data.
Some of the vendors listed above process data outside the European Economic Area. Each is engaged under a data processing agreement incorporating the European Commission's Standard Contractual Clauses. Core platform data — tachograph files, driver records and infringements — is stored and processed in the EU; these vendors are involved only in the messaging, voice and assistant features.