FleetPath
Platform
Platform overviewAutonomous OperationsCompliancePricing
Owner-Operators and TruckersFleets and CarriersBrokers
Industries
Heavy HaulPermit photo to compliant dispatch packetAggregate and BulkScale ticket to billable tonsHazmat and TankerPapers, endorsements, and route checked before rollLong-Haul OTRKnow the load before you book itReeferEvery load watched to the degreePrivate FleetRun your trucks like the cost center they areSee all industries
AboutVisionInvestorsDisclosures
Sign inGet started
PlatformIndustriesHeavy HaulAggregate and BulkHazmat and TankerLong-Haul OTRReeferPrivate FleetFor TruckersFor FleetsFor BrokersPricingCompanySign in
Security and Trust

Your operation runs on it.
We secure it that way.

How FleetPath protects your data: encryption, tenant isolation, access control, and the controls we are building toward SOC 2.

Security posture, reviewed and updated regularly

Data encryption

Every connection to FleetPath is encrypted, and sensitive stored data is protected at rest.

In transit

All public surfaces terminate TLS and enforce TLS 1.2 or higher. There is no plaintext listener. Transport encryption is enforced by the managed edge and hosting platforms that front the service.

At rest

The databases and file storage that hold your operational records run on managed cloud platforms that provide storage-level encryption at rest. On top of that, the most sensitive secrets we hold, your third-party integration credentials such as API keys and access tokens, are encrypted a second time at the application layer using authenticated symmetric encryption, under a server-side key kept separate from the data, with masked display and key-rotation metadata.

On the roadmap.We are adding application-layer field-level encryption for a small set of restricted direct identifiers, such as driver's license and taxpayer identification numbers, as an additional layer of defense in depth beyond platform encryption at rest. This is planned work, not yet in place.

Tenant isolation

FleetPath is a multi-tenant platform built on PostgreSQL. Every carrier organization is a separate tenant, and one tenant cannot read another tenant's data.

Isolation is enforced in two places. Every tenant-owned table carries a tenant identifier and is protected by row-level security policies for any direct database access. The server-side application layer, which runs with elevated privileges, additionally enforces a mandatory per-request tenant scope on every handler, and background workers use a helper that automatically chains the tenant filter so a forgotten scope is structurally prevented rather than left to chance.

As of today, row-level security is enabled on every tenant-owned table in production, and a continuous-integration guard blocks any new table from shipping without it.

Access control

Access to your organization's data follows the principle of least privilege: people and automated processes get only the access they need to do their work.

  • Role-based access control. A tenant-configurable permission resolver enforces role-scoped access. Sensitive permissions fail closed, denying access if the resolver cannot make a clean determination, and core owner and administrator protections cannot be revoked by misconfiguration.
  • Authentication. Sign-in is handled by our identity provider, and FleetPath does not store user passwords. Multi-factor authentication using a time-based one-time passcode is available, with hashed single-use recovery codes and audited recovery flows.
  • Credential protection. Third-party credentials you connect are encrypted at rest, shown only in masked form, and can be rotated.
  • Audit logging of sensitive access. Every access to a stored credential is recorded with the tenant, provider, action, actor, address, and device. Significant actions across the platform are written to a canonical audit log, stamped with the actor and whether the actor was a person or an automated process.

Financial integrity

Money math in FleetPath is deterministic and independently checked. Totals on statements, invoices, and settlements are computed with exact decimal arithmetic and hard-checked against their line items before any document is generated. A language model never produces a figure that lands on a financial document.

An append-only ledger of financial adjustments serves as the audit trail for money movement, so the history behind any balance can be reconstructed.

Data lifecycle

Your data is yours. You can take it with you, and you can have it deleted.

Export

You can export your operational records in machine-readable form. If your agreement ends, you keep access to export your data for a defined window before deletion begins. A full-account export (JSON, CSV, and your stored documents) is available, alongside machine-readable exports across the product.

Deletion

Account deletion is a self-service, retention-aware flow. When you delete your account, your data is soft-deleted immediately and then hard-deleted once the applicable retention window has elapsed. Some record classes carry legal retention floors, for example DOT and FMCSA record-keeping and IFTA and tax periods, and any records under a legal hold are preserved. Those are retained in restricted form for exactly as long as the obligation requires and then deleted. Transient processing artifacts, such as document-analysis screenshots, are swept on a short cycle measured in hours to days.

Application security

Security is part of how we build and operate, not a bolt-on.

  • Secret management. Secrets are kept out of source control and are scanned for. Error diagnostics are captured with credentials stripped before storage.
  • Incident response. We maintain incident-response runbooks and a data-breach notification plan, along with secret-rotation and recovery runbooks. Our plan is to notify affected customers of a data breach promptly, within 72 hours of becoming aware of it.
  • Change control. Database changes ship as reviewed, version-controlled migrations, and code-ownership review gates changes to sensitive paths.
  • Recurring internal security reviews. We run recurring internal security audits, including a systematic adversarial vulnerability-hunt program that has produced real fixes across the platform.

Infrastructure

FleetPath processes your data on cloud infrastructure located in the United States, and the service is operated from the United States. The subprocessors that handle personal data on our behalf are configured for United States processing. See our Subprocessors page for the current list of who touches what, and why.

Durable workflow orchestration provides retry and recovery for long-running operations, so work resumes rather than being lost if a component restarts.

Working toward SOC 2

FleetPath is building toward a SOC 2 examination. We are not SOC 2 certified today, and we do not hold a SOC 2 report or any other third-party security attestation. We say so plainly rather than imply otherwise.

Our security program is documented against the SOC 2 Trust Services Criteria in an internal controls matrix. As of today, 38 of the 52 controls in that matrix are implemented, with the remaining 14 planned before we engage an independent examiner. The architecture already earns confident language: tenant isolation by row-level security, a tamper-evident audit log, deterministic financial math, and code-ownership review of sensitive changes.

Work still ahead of the examination includes items such as extending multi-factor authentication enforcement to every workforce account and all production access, application-layer field-level encryption of the most sensitive identifiers, a formal risk register and vendor risk assessments, a documented access-review cadence, tested backup-and-restore procedures with stated recovery objectives, and an independent third-party penetration test. These are planned, and we will describe them as done only once they are.

Security questions or disclosuresadmin@fleetpath.app

See also Subprocessors, Data Processing Addendum, Privacy Policy.

FleetPath

The operations platform for American trucking. Snap the rate con and FleetPath builds the load, plans the truck-legal route, and lines up the invoice.

Industries

Heavy HaulAggregate and BulkHazmat and TankerLong-Haul OTRReeferPrivate Fleet

Product

PlatformAutonomous OperationsCompliancePricing

Company

AboutVisionInvestorsContact

Legal & Compliance

Privacy PolicyTerms of ServiceSubprocessorsSecurity & TrustData Processing AddendumAcceptable UseCarrier Bill of RightsCookie PolicyAccessibilityDisclosures
© 2026 FleetPath Technologies, Inc. All rights reserved.Built for the people who move America.
FleetPath Technologies, Inc. is a Delaware corporation and a wholly-owned subsidiary of Lavish Enterprises, Inc., which is publicly traded under the symbol VXIT. Nothing on this site is an offer to sell, or a solicitation of an offer to buy, any security, and nothing here should be relied upon in connection with any investment decision.