Skip to content

Security

Fleet data is the whole point of trust

You are asking us to watch your vehicles, your cargo, and your drivers. Here is exactly how we protect that — written plainly, not buried in a PDF.

Full detail, sub-processors, and completed questionnaires are available under NDA on request.

  • AES-256

    Encryption at rest

  • TLS 1.2+

    Encryption in transit

  • MFA

    Required for all staff access

  • 30 days

    Confirmed deletion requests

Controls

What is actually in place

Six areas, and the specific mechanism in each. If you need detail on any one of these, ask — we will give you the technical answer rather than the brochure one.

Encryption everywhere

All traffic between your devices, the API, and our platform runs over TLS 1.2 or higher. Data at rest — databases, backups, and stored video — is encrypted with AES-256. Credentials and secrets are held in a dedicated secrets manager, never in code or configuration files.

  • TLS 1.2+ in transit
  • AES-256 at rest
  • Secrets managed, not hardcoded

Access on a need-to-know basis

Customer data is visible only to staff whose role requires it. Access is authenticated with multi-factor authentication, granted on a least-privilege basis, and logged. Production access is time-limited and reviewed rather than standing.

  • MFA required for staff
  • Least-privilege grants
  • All access logged

Isolation and deployment hygiene

The platform runs on auto-scaling cloud infrastructure with network segregation between environments. Production is never used as a testing environment, and production data is not copied into staging.

  • Segregated environments
  • No production data in test
  • Patch cadence: monthly criticals

Backups that are actually tested

Backups are encrypted, retained on a rolling schedule, and — critically — restored on a schedule. A backup nobody has restored is a hypothesis, not a safeguard. We verify recovery regularly rather than trusting that the job reported success.

  • Encrypted, rolling backups
  • Scheduled restore drills
  • Documented RTO and RPO

Monitoring and incident response

Systems are monitored continuously for anomalous access, unusual query volume, and failure conditions. Alerts route to on-call engineers. We run a defined incident process with severity levels, named owners, and post-incident reviews that produce tracked corrective actions.

  • 24/7 alerting
  • On-call rotation
  • Post-incident review

Your data belongs to you

We do not sell fleet data, share it with advertisers, or use it to train third-party models. One-click export in standard formats is available at any time — including after cancellation — so leaving is always possible and never punishing.

  • No data resale
  • No third-party training
  • One-click export, any time

Engineering practice

Boring process, fewer incidents

Nothing glamorous here. This is the set of habits that keeps a platform handling live location data for other people’s businesses available and intact.

  • Dependency and vulnerability scanning as part of the build pipeline
  • Code review required before anything merges to the main branch
  • Separate development, staging, and production environments
  • Secrets rotated on a schedule and immediately on staff departure
  • Device authentication so a tracker must be bound to a fleet before reporting
  • Rate limiting and abuse protection on the API and public forms
  • Anti-jammer detection options available on supported hardware
  • Data export in open, documented formats

Found something? Tell us.

We welcome responsible security research. If you find a vulnerability in the platform, send the details and we will work on it properly.

  • Email info@axiontrack.com with a description and reproduction steps.
  • We acknowledge reports within two business days.
  • We will keep you updated while we work, and credit you in the disclosure if you want.
  • We do not take legal action against good-faith research that stays within our systems and gives us reasonable time to fix the issue.

Security FAQ

Questions your IT team will ask

Do you sign security questionnaires?

Yes. We complete standard vendor security questionnaires and are happy to sign a mutual NDA first if that comes before the paperwork. Send the questionnaire to our address and we will turn it around.

Can we get a dedicated server or isolated database?

Yes, on enterprise agreements. Dedicated allocation and isolated tenancy are available where your compliance requirements need them — discuss this during the quote so it is costed correctly.

How do you handle a breach?

We follow a defined incident process: contain, assess, remediate, then notify. Where your data is affected we will tell you what happened, what data was involved, and what we have changed to prevent it recurring — in plain language, and without waiting for every detail to be perfect.

How do I report a vulnerability?

Email info@axiontrack.com with the details. We acknowledge reports within two business days and will keep you updated as we work on it. We do not take legal action against researchers who act in good faith, stay within our systems, and give us reasonable time to fix before disclosure.

Where is our data stored?

On cloud infrastructure we operate, in-region where commercially and technically available. Your precise hosting location, sub-processors, and data residency options are documented in your order — ask us and we will tell you exactly rather than being vague about it.

What about our drivers’ privacy?

That is your responsibility as the data controller, and we give you the tools to handle it properly: scoped user permissions, configurable retention, and export for subject access requests. We are happy to advise on notice wording and consent flows for driver monitoring.

Due diligence

Need it in writing?

Send us your security questionnaire or request the full pack. We will also happily put an NDA in place first. Email info@axiontrack.com or ask below.

Prefer to talk first? Message us on WhatsApp · 0322-4644489