Security at TransportMgr
Security is built into TransportMgr from the database up, not bolted on later. Every record is scoped to your organisation, encrypted in transit and at rest, and every change is logged. The summary below covers the controls that matter most to transport operators.
Tenant isolation
The platform is multi-tenant by design. Every record is scoped to your organisation at the database level, so your data is logically separated from every other customer's.
Encryption
Data is encrypted in transit using TLS and encrypted at rest. Card details are handled directly by our payment providers and are never stored on our systems in full.
Strong authentication
Multi-factor authentication via TOTP, single sign-on with Microsoft Entra ID, and OAuth with Google and Microsoft. Access is governed by role-based permissions you control.
Audit logging
Every create, update and delete is recorded with a full audit trail, so you can see who changed what and when across your organisation.
Data residency
We operate globally with regional data residency options, so you can keep data in a particular country where you need to.
Your data, exportable
You can export your bookings, customers, vehicles, drivers, invoices and compliance records as CSV or via the API at any time. After cancellation we keep data available for 90 days.
Regulatory alignment
Out of the box we align with UK GDPR, EU GDPR, US state privacy laws including CCPA and CPRA, Nigeria's NDPA 2023, Kenya's Data Protection Act 2019 and South Africa's POPIA. See our privacy policy for how we handle personal data and the terms of service for the contractual commitments that sit behind the Service.
Reporting a vulnerability
If you believe you have found a security issue, please tell us before disclosing it publicly so we can investigate and fix it. Email [email protected] with the details and steps to reproduce, and we will acknowledge your report and keep you updated.