Last updated: June 22, 2026
Brokers trust HaulProof with sensitive operational data, and we treat that responsibility seriously. This page summarizes how we protect your information. We're happy to walk security teams through it in more detail.
All traffic to and from HaulProof is encrypted in transit using TLS (HTTPS). Data at rest is stored on managed cloud infrastructure with provider-level encryption.
Passwords are never stored in plain text. We hash them with scrypt, a memory-hard algorithm, using a unique random salt per password and constant-time comparison. Sessions use long, random tokens delivered in secure, HTTP-only cookies, so credentials are never exposed to client-side scripts.
Every customer operates in their own isolated workspace. Users only ever see data belonging to their own organization, and roles (admin, accounting, agent) govern what each person can do. Administrators manage their own team's access.
HaulProof runs on managed cloud hosting that is independently certified to SOC 2 Type II and ISO 27001, with durable, backed-up storage. Secrets such as API keys live in a managed environment store, never in our source code and never exposed to the browser.
Queried live: FMCSA and SAFER for authority, safety and insurance filings; NHTSA for VIN; Secretary of State corporate registries. Any check we cannot answer reads PENDING and blocks approval — it never passes quietly.
Checked by your team, not by us: Carrier411 and FreightGuard. Their Web Services interface is a paid add-on we do not hold, so the record carries a named person’s attestation of what they saw and when, rather than an API call we never made.
Behind the framework: the 22 checks are built on Verisk CargoNet and TIA State of Fraud research. Sentry adds NWS weather and live traffic where relevant. All of it is business data about motor carriers, used to produce vetting results and a defensible audit record.
The Sentry assistant sends only the data needed to answer your question to our AI provider (Anthropic). That data is used to generate your response and is not used to train third-party models.
We monitor the platform's availability and keep durable records of vettings and account activity so your audit trail persists.
Our infrastructure is certified to SOC 2 Type II and ISO 27001. HaulProof’s own company-level certification is on our roadmap — we hold ourselves to those controls today, and we do not claim an audit we have not completed. We can provide a signed DPA and support SSO for qualifying plans.
If you believe you've found a security issue, please email hello@haulproof.ai with the details. We appreciate responsible disclosure and will respond promptly.