Trust & Safety
Your business data is valuable. Here's how we protect it — described honestly.
Last updated: September 15, 2026
Data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256 by our infrastructure provider.
Hosted on established cloud infrastructure (Supabase, built on AWS) with DDoS mitigation at the network edge.
Row Level Security and server-side tenant checks are designed so each company can access only its own data.
Automated daily backups of core business data help us recover from data-loss events.
Application error and performance monitoring via Sentry, with alerting, so we can investigate and remediate issues.
Industry-standard password hashing via our authentication provider, optional two-factor authentication (TOTP), and sessions that expire.
We use security controls that are designed to protect your data, and we describe them accurately. No online service can be guaranteed to be completely secure, and we do not claim to be. This page reflects the controls we actually have in place; where we rely on a third-party provider for a control, we say so.
DumpTruckBoss runs on Supabase (built on Amazon Web Services). We do not operate our own physical servers. Our deployment uses:
Our infrastructure providers (Supabase and AWS) maintain their own independent, third-party security certifications — such as SOC 2 — for the platforms and facilities they operate. DumpTruckBoss itself is not currently SOC 2, ISO 27001, PCI, or HIPAA certified, and we do not represent that it is.
Data is protected in transit and at rest:
DumpTruckBoss is multi-tenant. Data isolation is enforced by a combination of server-side authorization checks in our application and PostgreSQL Row Level Security (RLS):
DumpTruckBoss personnel do not access customer data in the ordinary course of business. When a member of our team accesses a customer account for support or troubleshooting, that access is restricted and recorded in an internal audit log.
Backups exist to help recover from data-loss events. Because backups are retained for a period after data is created or deleted, information you delete may persist in backups for a limited time before it ages out.
We monitor the application and respond to issues:
If we confirm a security incident affecting your data, we will investigate, contain, and remediate it, and notify affected customers and any regulators or authorities where and when required by applicable law or our contract with you, without undue delay. We do not commit to a single universal notification deadline for every situation.
Security is shared. You are responsible for keeping your login credentials confidential, enabling two-factor authentication, managing who on your team has access, and using GPS, location, driver, and personal information you put into DumpTruckBoss in compliance with the laws that apply to you — including providing any notices and obtaining any consents required before tracking drivers, employees, contractors, or vehicles.
We take security reports seriously. If you discover a vulnerability in DumpTruckBoss, please report it to us privately before disclosing it publicly. We aim to:
We do not currently operate a paid bug-bounty program.
Report a vulnerability
Email: security@dumptruckboss.com. See also our security.txt.
For security questions, vendor assessments, or privacy inquiries, contact security@dumptruckboss.com or privacy@dumptruckboss.com.