Security & Trust Overview

Last updated: 7 June 2026

1. Our commitment to security

Security and data protection are central to FreightVIS. As a platform handling logistics operations, payment and financial data, location and telematics data, and client data, we apply layered technical and organisational controls designed to protect the confidentiality, integrity, and availability of that information. This overview summarises our approach; customers under NDA may request additional detail.

2. Compliance and frameworks

We design our security program around recognised frameworks, including the Australian Cyber Security Centre's Essential Eight, and we handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). Card payment data is processed by a PCI DSS-compliant payment provider (Stripe).

We do not currently hold formal third-party certifications such as ISO/IEC 27001 or SOC 2. We are happy to share details of our current controls and practices with customers and prospects under NDA.

3. Hosting and infrastructure

  • The Service is hosted on reputable cloud infrastructure — Supabase (PostgreSQL database, authentication, and storage) and Vercel (application hosting).
  • Production environments are logically separated from development and test environments.
  • Our infrastructure providers and their processing locations are listed in our Subprocessor List.

4. Encryption

  • In transit: data is encrypted using TLS 1.3 for connections to the Service and its APIs.
  • At rest: customer data, including backups, is encrypted at rest.
  • Sensitive credentials: third-party OAuth tokens (such as accounting integrations) are encrypted using AES-GCM 256-bit encryption with per-token random salts and key derivation.

5. Access control and authentication

  • Role-based access control (RBAC) across a defined role hierarchy, applying least-privilege principles.
  • Multi-factor authentication (MFA) is available to users and required for administrative and privileged roles.
  • Configurable session controls, including idle and absolute session timeouts and limits on concurrent sessions.
  • Login rate limiting and account-protection controls.
  • Audit logging of significant account and administrative actions.

6. Network and application security

  • Nonce-based Content Security Policy (CSP) with no inline scripts permitted.
  • Rate limiting on authentication and public endpoints, which fails closed in production.
  • Server-side input validation on API requests.
  • Secure software development practices, including peer code review and a security-focused CI pipeline.
  • Automated dependency and secret scanning, static analysis, software bill of materials (SBOM) generation, and automated dynamic application security testing (including OWASP ZAP scans). Findings are tracked to remediation.

7. Multi-tenancy and data segregation

The Service uses a multi-tenant architecture in which each organisation's data is logically segregated. Row-level security (RLS) policies are enforced at the database level on every table, so users can access only the data belonging to their own organisation.

8. Payment and financial data

Card payment data is processed by Stripe, a PCI DSS-compliant payment provider. Billing details are provided directly to Stripe and we do not store full card numbers on our own systems. Financial and transactional data within the Service is protected by the access, encryption, and logging controls described above.

9. Location and telematics data

Location and telematics data is treated as potentially personal information and protected accordingly. Customers control the collection settings within their account and are responsible for any notices or consents required for tracking. We apply access controls and encryption to this data and retain it according to configurable retention settings.

10. Backups and resilience

We maintain regular, encrypted backups stored separately from the primary environment, and we follow documented procedures for data recovery. Our infrastructure providers offer provider-managed redundancy.

11. Logging and monitoring

We maintain centralised logging, audit trails, and system health monitoring across the Service to help detect and respond to anomalous or unauthorised activity.

12. Personnel

Personnel are bound by confidentiality obligations, and access to systems and data is granted on a need-to-know, least-privilege basis.

13. Incident response and breach notification

We maintain an incident response process with defined escalation paths. If a data breach likely to result in serious harm occurs, we follow the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth) and notify affected customers and, where required, the Office of the Australian Information Commissioner (OAIC) and affected individuals.

14. Responsible disclosure

We welcome reports of suspected vulnerabilities. Please contact support@freightvis.com with details. We ask that researchers act in good faith, avoid privacy violations and service disruption, and give us a reasonable opportunity to remediate before any public disclosure.

15. Privacy and contact

Our handling of personal information is described in our Privacy Policy. For security or procurement enquiries, contact us at:

  • Email: support@freightvis.com
  • Post: FreightVIS, Australia