Trust & Safety
Your business data is valuable. Here's how we protect it.
Last updated: April 30, 2026
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Backups are encrypted before leaving our servers.
Hosted on enterprise-grade cloud infrastructure with redundant availability zones, DDoS protection, and automated failover.
Row-level security ensures each company can only access its own data. Employee access to production data is restricted and audited.
Automated daily backups with point-in-time recovery. We can restore any account to any minute within the last 7 days.
24/7 uptime monitoring, anomaly detection, and automated alerts. Incidents are investigated and resolved with full post-mortems.
Secure password hashing (bcrypt), optional two-factor authentication (TOTP), and session management with automatic expiry.
DumpTruckBoss runs on Supabase (built on AWS), one of the world's most reliable cloud infrastructure providers. Our deployment uses:
Our physical infrastructure is housed in SOC 2 Type II certified data centers. We do not operate our own physical servers.
All data is protected at every layer:
Multi-tenant data isolation is enforced at the database level using Row Level Security (RLS):
DumpTruckBoss employees do not have routine access to customer data. When access is required for support purposes, it requires explicit authorization and is logged.
We maintain continuous monitoring across our systems:
In the event of a confirmed security incident affecting your data, we will notify affected customers by email within 72 hours of discovery, in accordance with applicable regulations.
We take security reports seriously. If you discover a vulnerability in DumpTruckBoss, please report it to us privately before disclosing it publicly. We commit to:
Report a vulnerability
Email: security@dumptruckboss.com — PGP key available on request.
For security questions, vendor assessments, or compliance inquiries, contact security@dumptruckboss.com.