Security & trust

An honest, concise description of what we run to protect your vehicle data - infrastructure, controls and standards. No marketing fluff.

HostingHetzner Cloud
RegionNuremberg, DE (EU) - primary hosting; some providers process elsewhere, see Subprocessors
BackupsDaily
Posture reviewedMay 2026

What runs in production today

No half-truths. The same answers we give to enterprise security questionnaires.

Encryption in transit

TLS via Let's Encrypt for all web traffic. The Codec 8E ingest socket on port 5027 runs in a private network segment, and tracker traffic over 1NCE SIMs is constrained to our endpoint.

Per-tenant database isolation

Each customer workspace lives in its own MariaDB 11.4 database. A workspace cannot read or write any other workspace's data at the database level, not just at the application level.

EU hosting on Hetzner

The application and GPS ingest listener run on a Hetzner Cloud CPX22 instance in Nuremberg, Germany, and your data is stored there. Hetzner data centres are ISO/IEC 27001 certified. Some providers we use process data outside the EU; each one, and where it processes, is listed under Subprocessors.

Daily backups

Full application and database backups run daily and are retained for 14 days. Backups are encrypted at rest. We test restore procedures regularly.

Hashed passwords + MFA on admin

User passwords are stored with bcrypt. Time-based two-factor authentication is available to all users and required for super-admin (/bss) accounts.

Role-based access control

Granular permissions inside each workspace. Vehicles can be shared read-only via tokenised links. Audit logging records every administrative action.

Segregated OS users

The application runs under a non-root user managed by CloudPanel. Database, web and queue workers run with the minimum privileges they need.

Secrets out of source control

Credentials and API keys live in environment variables on the server, never in git. Access to the production server is keyed and limited to named operators.

CSRF + rate limiting

CSRF tokens on every state-changing form. Login, register and contact endpoints are rate-limited to slow credential-stuffing and abuse attempts.

Audit logging

Administrative actions, logins and security-relevant events are written to a tamper-evident audit log retained for at least 12 months.

What we cover

Mapped to the standards procurement teams ask about. We do not claim what we cannot hold.

StandardStatusNotes
EU GDPR Our own assessment We act as processor for customer data and controller for our own site and billing; a DPA is ready to sign. GDPR provides for certification schemes (Articles 42 and 43) and we hold none, so this row is our own assessment, not a badge.
US state privacy laws (CCPA/CPRA and similar) Rights honoured either way We do not sell personal data and we do not share it for cross-context advertising. Which of these statutes reaches a company our size turns on thresholds that differ by state and change year to year, so we rest nothing on that: we answer access, correction and deletion requests from anybody who asks, and the retention and security commitments in our Privacy Policy apply to every customer wherever they live.
ISO/IEC 27001 (hosting) Provider only We are not certified. Our hosting provider Hetzner is, which covers their data centres - not our application, our code or our processes.
SOC 2 Type I (SimpleGPS) Not held We do not hold one and no audit is under way. A date will appear here when there is one.
PCI-DSS Reduced, not removed Card numbers never reach our servers - Stripe handles them and is a PCI-DSS Level 1 service provider. That reduces our obligation to the simplest self-assessment; it does not remove it.

Trusted stack

The vendors behind the service. Full list and roles in subprocessors.

Hetzner Cloud
Hosting · EU region · ISO 27001
Stripe
Payments · Stripe is PCI-DSS Level 1
SIM
IoT connectivity for tracker SIMs
Teltonika
Tracker manufacturer
Cloudflare
DNS · TLS · DDoS protection