Security you can check, not just read about.

We build software that makes hazmat compliance provable, so we hold ourselves to the same standard. Here is our security posture — the controls that run continuously, the frameworks we're working toward, and a plain list of the things we do not claim.

Continuous control monitoring

Our security controls aren't a once-a-year checklist. Sixty-two automated tests run continuously against our live infrastructure, identity provider, code repositories, and endpoints — checking encryption, access, logging, backups, and vulnerability management, and alerting us the moment one of them drifts.

62
automated security controls monitored continuously
62 / 62
passing as of August 2, 2026
19
security policies documented, approved, and reviewed annually

Live control status

Our continuously monitored control status is published through our compliance platform's trust center. It isn't public yet — until it is, we'll send the current status, our security overview, and any diligence documentation on request.

Request our security overview

Where we are on SOC 2

SOC 2 Type I readiness is in progress. We are not SOC 2 certified, and we won't say otherwise until we hold a report.

Concretely: our control set, policies, and evidence are being built and monitored against the SOC 2 Security Trust Services Criteria. No audit has been completed, and no independent auditor has issued an opinion on our controls. We're also building toward NIST SP 800-171 for customers whose contracts require it.

If your procurement process needs a firm date or a specific artifact, ask us — we'd rather tell you exactly where we are than let a badge imply something we haven't earned.

What's actually in place today

What we don't claim

Every vendor's security page tells you what they have. This is the part that's usually missing, and it's the part worth reading.

Questions, or a security review to run?

Send security questionnaires, diligence requests, or vendor-review paperwork to zackary@haulguard.ai — or use the contact form. To report a vulnerability, follow our vulnerability disclosure policy and put [security] in the subject line so it doesn't get triaged with general inbound.

HaulGuard AI assists with and documents hazmat compliance decisions; it does not replace the carrier's or shipper's own legal obligations under 49 CFR, and it is not affiliated with or endorsed by DOT, PHMSA, or FMCSA. AI extraction is best-effort — verify every field; your verification is the record.