Security

What FleetReform does today to keep one customer's data away from another's, stated plainly - including what it does not have yet.

Workspace separation

Every customer has its own workspace. Each request to the API is scoped to the workspace of the signed-in person, on the server, before any data is read. Automated tests run against a real database to confirm that one workspace cannot read another's bookings, vehicles, maintenance, energy logs, alerts, audit log, or reports.

Sign-in and access

  • Sign-in is handled by Clerk. FleetReform does not store passwords and has no password field in its database.
  • There are five roles: Owner, Admin, Fleet manager, Driver, and Mechanic. Each role's access is enforced on the server, not only hidden in the interface.
  • Changes to records are written to an audit log with who made the change, what changed, and when.
  • Clerk's sign-up events reach FleetReform through webhooks whose signatures are verified before anything is processed.

Data in transit and uploads

  • The API accepts HTTPS connections only.
  • Receipt photos and workspace logos go straight from the device to storage using a link that expires after five minutes. They do not pass through the API.
  • The storage location of an upload is built from the signed-in person's workspace, never from anything the client sends.

Where data is hosted

The API runs in Frankfurt, Germany. The full list of services that handle customer data, and what each one receives, is on the subprocessors page.

What FleetReform does not have yet

  • No third-party security certification or attestation.
  • No independent penetration test.
  • No published uptime commitment. The API may take a few seconds to answer the first request after a quiet period.
  • No documented backup and restore procedure to share.

If your security review needs something not listed here, ask. We will say what exists and what does not.

Reporting a vulnerability

Email support@tsunava.comwith the subject line "Security" and enough detail to reproduce the problem. Please do not access data that is not yours or disrupt the service while testing. This is a request for responsible reporting, not a bug bounty or a legal safe harbor.