We secure it the way we'd want our own carrier's data secured. Encryption everywhere, isolation per tenant, audit logging on every privileged action, and zero data resale — ever.
Encrypted at rest (AES-256). TLS 1.3 in transit. Row-Level Security ensures no carrier ever sees another carrier's data — enforced at the Postgres level, not just the application.
Field-level encryption for the most sensitive records. Access logged and rate-limited. Retention follows 49 CFR retention rules (typically 3 years rolling).
Stored with your tenant for audit defense. Used to improve your Compass experience only. Never sold. Never shared with other carriers. Anthropic doesn't train models on your conversations under their commercial terms.
All data in transit. No exceptions.
Supabase-managed Postgres encryption.
No carrier sees another carrier's data, enforced at the DB.
Every privileged action logged. 7-year retention.
Your driver/carrier data is never sold or shared.
Type II target in Year 2 as Enterprise tier scales.
$2M errors-and-omissions on AI-driven advice.
Platform code on GitHub. Inspect every line.
Enterprise customers can request a Data Processing Agreement (DPA) at signup. For specific questions, email us.