Security

Trust requires security.

CarrierAxis is designed so sensitive transportation and driver information is controlled by permissions, tenant boundaries, and server-side authorization.

Multi-Tenant Architecture

Every carrier runs on the same application but receives its own isolated workspace.

Row Level Security

Per-carrier data separation enforced at the database level — not just hidden in the UI.

Role-Based Permissions

Granular permission strings like fleet.view, driver.sensitive_view, and mvr.request.

Server-Side Authorization

Sensitive fields require dedicated authorized server functions. Tenant membership alone is not sufficient.

Encrypted Sensitive Fields

Driver license and DOB stored encrypted; only masked values returned to ordinary queries.

Audit Logging

Every administrative and verification action records who, which company, what, and when.

Fail-closed by design

When a live external service is unavailable, CarrierAxis says it's unavailable — it never fabricates or substitutes data. Provider secrets are server-only and never exposed to the browser. Consent is required before any protected report is requested.