Skip to main content

Security & Trust

A product-facing summary of how HAULIC protects access, isolates tenant data, and keeps dispatch operations moving.

Trust centerLast reviewed: July 21, 2026

Security that protects dispatch speed.

HAULIC pairs tenant isolation, audit trails, and edge protections so teams can move fast without losing control of the operation.

Least-privilege access

Server-enforced RBAC with privileged re-authentication

Tenant isolation

company_id scoping keeps operational data company-bound

Edge defense

Cloudflare-fronted traffic with headers and rate limiting

Secure access without slowing dispatch

Authentication is built to keep access tight while still making day-to-day work feel fast and predictable.

  • Password policy requires 12+ characters with upper, lower, numeric, and symbol requirements.
  • MFA is available for user accounts through TOTP.
  • Repeated failed login or MFA attempts trigger account lockout.
  • Privileged re-authentication is required before sensitive exports and admin actions.
  • Session revocation is available from the Security settings surface.

Tenant boundaries that stay invisible to users

HAULIC is designed around tenant-isolated operational data, so company context stays contained at every layer.

  • Operational data is scoped to company_id at the query layer.
  • Tenant database routing is used for company-owned records.
  • Cross-tenant context switching is restricted to master_admin accounts.
  • Server-side RBAC covers dispatcher, lead_dispatcher, company_admin, owner, sales, accounting, and master_admin.
  • Export paths are treated as elevated workflows and are separately controlled.

Audit trails that stand up in review

Security and audit events are captured so reviews, investigations, and accountability checks are straightforward.

  • Immutable audit logs are written for load creation, updates, status transitions, and driver or truck changes.
  • Security events capture failed logins, MFA failures, lockouts, and suspicious activity.
  • Monthly automated security checks feed the admin dashboard.
  • Audit-log query and export workflows support date and company filtering for investigations.
  • Tenant safety audit coverage supports cross-tenant assignment checks and visibility review.

Protected at the edge

Public traffic sits behind the edge, where transport security and request controls can be enforced consistently.

  • Cloudflare fronts the public experience with HTTPS and HSTS in place.
  • Security headers include CSP, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy.
  • Layered rate limiting covers global, auth-specific, and expensive routes.
  • Attack-mode controls can throttle bursts of anomalous traffic.
  • Origin access is intended to remain restricted behind proxy controls and secret checks.

Safety checks before a load moves

Dispatch workflow is tied to safety checks so compliance issues surface before a load can be assigned.

  • Trucks with expired annual inspections or out_of_compliance status cannot be assigned to loads.
  • The Driver Qualification File registry tracks CDL class, med card expiry, MVR status, and Clearinghouse status.
  • Compliance state is visible to dispatch roles and hard-locks are surfaced prominently.
  • Safety checks are treated as operational guardrails, not just reference data.
Built for enterprise scale

The structure is intentionally simple so it can grow into a fuller trust center later with proof points, control owners, and policy references.

  • Evidence links can be added once the source list is approved.
  • Policy dates and attestations can be surfaced for a more formal trust-center feel.
  • Incident response and backup validation can be expanded without changing the layout.

Responsible disclosure

Report security issues to security@haulic.app with reproduction details, impact assessment, and affected endpoints. We aim to acknowledge reports within 2 business days.