FleetTrestle Trust Center

Security and data practices in one place.

Review the controls, data practices, service information, accessibility posture, integrations, and customer contact paths that support FleetTrestle.

Trust directory

Find the evidence behind the platform.

Each destination describes the current product or policy. FleetTrestle does not use this page to imply certifications, uptime guarantees, subprocessors, integrations, or controls that are not actually in place.

Privacy

What FleetTrestle collects and how personal information is handled.

Review privacy →

Support

A direct path for security, privacy, accessibility, or service concerns.

Review support →

Security controls built into the platform foundation.

We describe what FleetTrestle actually uses today and avoid claiming certifications, audit results, uptime guarantees, or recovery guarantees that have not been independently earned or verified.

✓

Authentication

FleetTrestle uses Supabase authentication for account sign-in and session management instead of building a custom password system.

✓

Organization isolation

Customer records are scoped to the organization workspace, with row-level security used as an additional database boundary.

✓

Role-based access

Administrative actions such as team management, billing, and organization controls are restricted by role rather than being available to every signed-in user.

✓

Private files

Documents, issue photos, and receipts use organization-scoped storage paths, file validation, and short-lived signed download links rather than public attachment buckets.

✓

Billing

Subscription checkout and payment-method management are handled through Stripe-hosted payment experiences. FleetTrestle does not need to store raw card numbers in the application.

✓

QR authorization

A vehicle QR code is a routing convenience only. Authentication, organization authorization, and Driver ID verification for driver field work still apply before field actions are accepted.

✓

Internal operations

FleetTrestle's internal Autopilot area is separated from the customer workspace and protected by server-enforced owner access checks.

✓

Transport & secrets

Production traffic is served over HTTPS, while authentication, service, and billing secrets remain in protected server environments rather than client-side code.

Data lifecycle

Export, retention, and deletion stay visible.

Organization administrators have product paths for data export and account/data-management requests rather than needing an undocumented back-channel process.

Customer-held copyOrganization administrators can download fleet records and retain that copy under their own policy.
Files and attachmentsPrivate documents and photos are delivered through authenticated, organization-scoped access paths.
Backup and recovery

Keep an independent copy of your fleet records.

FleetTrestle uses managed infrastructure, and organization administrators can download a copy of their fleet records from the application.

Recovery procedureService recovery is designed around restoring application access, validating organization boundaries, reconciling billing state, and checking critical fleet workflows before normal operation resumes.
Restore validationBackup and restore behavior is verified through production-like rehearsals; FleetTrestle does not turn internal evidence into an unsupported contractual recovery guarantee.
No invented SLAFleetTrestle does not advertise a recovery-time or recovery-point guarantee that has not been contractually established and operationally supported.
Incident handling

Contain, assess, recover, document.

The security posture includes a defined response sequence for suspected access, secret, organization-isolation, or service-integrity incidents.

Contain accessRestrict affected paths and rotate exposed credentials or secrets when necessary.
Preserve evidenceRetain relevant logs and deployment context so the cause and customer impact can be assessed.
Recover safelyVerify authentication, organization isolation, uploads, billing state, and other affected workflows before considering the incident resolved.
Communicate appropriatelyAffected customers are notified when legal, contractual, or material-impact considerations require it.
Responsible posture

No inflated trust claims.

FleetTrestle will only advertise formal certifications, audit results, uptime guarantees, or compliance designations after those claims are supportable.

Least privilegeAccess should be limited to the organization and role a user needs.
Server-side secretsService credentials and billing secrets belong in protected server environments, not client-side code.