Skip to content

Security & compliance

Built to pass the audit, not just the demo

Enterprise buyers ask hard questions about who can see their data and what happens when it matters. These are the controls FleetHQ actually enforces in the product today.

Hosted in Australia

Your fleet’s records are hosted in Australia, on Australian infrastructure — kept close to the operators who rely on it rather than shipped offshore.

Tenant isolation at the database

Row-level security enforces separation inside the database itself, not just in application code — every query is scoped to your organisation, so your data cannot leak into another operator’s view.

Role-based access control

Granular permissions per person, role and depot, denied by default. People see exactly what their job needs and nothing more, and access is refused unless a permission explicitly grants it.

Multi-factor authentication

MFA is available for account sign-in and can be required for privileged access, so a leaked password alone is not enough to get in.

Encrypted in transit

All traffic is encrypted in transit over TLS. Integration credentials are encrypted at the application layer and isolated per environment, never stored or shared in the clear.

A complete audit trail

Changes are recorded against an append-only timeline — who did what, and when — so you can reconstruct the history of an asset, job or record on demand.

Compliance evidence, captured live

Inspections, licences and inductions are logged as work happens, with Chain of Responsibility evidence packs you can export — audit-ready for NHVR, not reassembled the week of an audit.

Passwords checked against known breaches

When a password is set or changed, it is checked — using a privacy-preserving method that never sends the password itself — against billions of credentials exposed in known data breaches. If yours appears, it is refused before it can be used.

Staff access is logged, too

It is not only your team’s activity that is recorded. When FleetHQ support staff take an action on your account, it is written to a separate, append-only staff audit log — who did what, and when — so access to your data is accountable, not invisible.

Data residency
Australia
Tenant isolation
Row-level security
Access control
Role-based, deny by default
Sign-in
MFA available
In transit
TLS encryption
Record integrity
Append-only audit trail
Password safety
Checked against breaches
Staff access
Logged & audited
Apps
Web, iOS & Android