Security
Last updated: September 27, 2026
Tenant isolation
Every organization's data is scoped by organization at the application layer. Users can only query records belonging to their own organization, and role checks (admin / manager / technician) are enforced on every request. Platform administrators' cross-organization access is logged.
Encryption in transit
All traffic to fleetoms.com and the Fleet OMS API is served over HTTPS (TLS). Database connections in production use encrypted connectivity.
Encryption at rest
Production data is stored in AWS services (RDS, S3) with encryption at rest enabled.
Authentication
Sign-in uses short-lived signed session tokens (60 minutes) with server-side revocation on logout. Password changes and account deletion require re-authentication.
Password storage
Passwords are hashed with bcrypt — we never store or log plaintext passwords.
Roles and permissions
Access is role-based: technicians, managers, and organization admins each see and can change only what their role allows. Organization settings and billing are restricted to admins.
Payment processing
Subscriptions and payments are processed by Stripe. Card details are collected and stored by Stripe only — they never pass through or persist on Fleet OMS servers.
Backups and recovery
The production database runs on AWS RDS with automated backups and deletion protection. Regular on-site backups of the full application are kept for disaster recovery.
Logging and monitoring
Security-relevant events (authentication, permission denials, administrative actions) are logged with timestamps and source context. Service health is monitored continuously.
Data ownership, export, and deletion
You own your data. Organization admins can request an export at any time, and account deletion is self-service (with a 30-day reactivation window before permanent removal).
AI data use
Where AI features are enabled, customer data is used only to serve that customer's own requests within their organization. We do not sell customer data or use it to train third-party models.
Vulnerability reporting
Found a security issue? Email info@fleetoms.com with details. We take reports seriously and will work with you on responsible disclosure.
This page describes current implemented practices only and does not claim third-party certifications.