Security

Last updated: September 27, 2026

Tenant isolation

Every organization's data is scoped by organization at the application layer. Users can only query records belonging to their own organization, and role checks (admin / manager / technician) are enforced on every request. Platform administrators' cross-organization access is logged.

Encryption in transit

All traffic to fleetoms.com and the Fleet OMS API is served over HTTPS (TLS). Database connections in production use encrypted connectivity.

Encryption at rest

Production data is stored in AWS services (RDS, S3) with encryption at rest enabled.

Authentication

Sign-in uses short-lived signed session tokens (60 minutes) with server-side revocation on logout. Password changes and account deletion require re-authentication.

Password storage

Passwords are hashed with bcrypt — we never store or log plaintext passwords.

Roles and permissions

Access is role-based: technicians, managers, and organization admins each see and can change only what their role allows. Organization settings and billing are restricted to admins.

Payment processing

Subscriptions and payments are processed by Stripe. Card details are collected and stored by Stripe only — they never pass through or persist on Fleet OMS servers.

Backups and recovery

The production database runs on AWS RDS with automated backups and deletion protection. Regular on-site backups of the full application are kept for disaster recovery.

Logging and monitoring

Security-relevant events (authentication, permission denials, administrative actions) are logged with timestamps and source context. Service health is monitored continuously.

Data ownership, export, and deletion

You own your data. Organization admins can request an export at any time, and account deletion is self-service (with a 30-day reactivation window before permanent removal).

AI data use

Where AI features are enabled, customer data is used only to serve that customer's own requests within their organization. We do not sell customer data or use it to train third-party models.

Vulnerability reporting

Found a security issue? Email info@fleetoms.com with details. We take reports seriously and will work with you on responsible disclosure.

This page describes current implemented practices only and does not claim third-party certifications.