
Security & Trust
A product-facing summary of how HAULIC protects access, isolates tenant data, and keeps dispatch operations moving.
Security that protects dispatch speed.
HAULIC pairs tenant isolation, audit trails, and edge protections so teams can move fast without losing control of the operation.
Server-enforced RBAC with privileged re-authentication
company_id scoping keeps operational data company-bound
Cloudflare-fronted traffic with headers and rate limiting
Secure access without slowing dispatch
Authentication is built to keep access tight while still making day-to-day work feel fast and predictable.
- Password policy requires 12+ characters with upper, lower, numeric, and symbol requirements.
- MFA is available for user accounts through TOTP.
- Repeated failed login or MFA attempts trigger account lockout.
- Privileged re-authentication is required before sensitive exports and admin actions.
- Session revocation is available from the Security settings surface.
Tenant boundaries that stay invisible to users
HAULIC is designed around tenant-isolated operational data, so company context stays contained at every layer.
- Operational data is scoped to
company_idat the query layer. - Tenant database routing is used for company-owned records.
- Cross-tenant context switching is restricted to master_admin accounts.
- Server-side RBAC covers dispatcher, lead_dispatcher, company_admin, owner, sales, accounting, and master_admin.
- Export paths are treated as elevated workflows and are separately controlled.
Audit trails that stand up in review
Security and audit events are captured so reviews, investigations, and accountability checks are straightforward.
- Immutable audit logs are written for load creation, updates, status transitions, and driver or truck changes.
- Security events capture failed logins, MFA failures, lockouts, and suspicious activity.
- Monthly automated security checks feed the admin dashboard.
- Audit-log query and export workflows support date and company filtering for investigations.
- Tenant safety audit coverage supports cross-tenant assignment checks and visibility review.
Protected at the edge
Public traffic sits behind the edge, where transport security and request controls can be enforced consistently.
- Cloudflare fronts the public experience with HTTPS and HSTS in place.
- Security headers include CSP, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy.
- Layered rate limiting covers global, auth-specific, and expensive routes.
- Attack-mode controls can throttle bursts of anomalous traffic.
- Origin access is intended to remain restricted behind proxy controls and secret checks.
Safety checks before a load moves
Dispatch workflow is tied to safety checks so compliance issues surface before a load can be assigned.
- Trucks with expired annual inspections or out_of_compliance status cannot be assigned to loads.
- The Driver Qualification File registry tracks CDL class, med card expiry, MVR status, and Clearinghouse status.
- Compliance state is visible to dispatch roles and hard-locks are surfaced prominently.
- Safety checks are treated as operational guardrails, not just reference data.
The structure is intentionally simple so it can grow into a fuller trust center later with proof points, control owners, and policy references.
- Evidence links can be added once the source list is approved.
- Policy dates and attestations can be surfaced for a more formal trust-center feel.
- Incident response and backup validation can be expanded without changing the layout.
Responsible disclosure
Report security issues to security@haulic.app with reproduction details, impact assessment, and affected endpoints. We aim to acknowledge reports within 2 business days.
Next step