Security
Fleet data security.
Access to company records and connected vehicle data must follow the authenticated account, not a company identifier supplied by a browser.
Separation starts with identity.
Customer access is scoped to an organization. Vehicle data, reports, and Advisor context should stay within that scope. Fleet AI staff access is separate from customer access.
Security is an ongoing engineering process. This page describes the product's approach, not an independent certification or a guarantee that vulnerabilities cannot exist.
- Account access
- Passwords are hashed using bcrypt. Browser authentication uses server-managed sessions instead of storing an authentication token in local storage.
- Company records
- Authenticated organization scope is checked on customer requests. A vehicle or driver belonging to another organization is not an authorized reference.
- Connected devices
- Pairing associates a device with its company, vehicle, and driver. Keep pairing codes and device credentials private, and revoke access when assignments end.
- Advisor context
- Fleet data used for Advisor answers is scoped to the company making the request. Review the privacy notice for information about service providers.
Plan access before the pilot.
Identify who needs administrative access, who needs read-only access, and who will manage devices. Agree on the data to collect and the process for removing access when someone leaves.
Ask the Fleet AI team for current deployment controls, retention arrangements, and any security review your organization requires before sharing production data.