Security you can check, not just read about.
We build software that makes hazmat compliance provable, so we hold ourselves to the same standard. Here is our security posture — the controls that run continuously, the frameworks we're working toward, and a plain list of the things we do not claim.
Continuous control monitoring
Our security controls aren't a once-a-year checklist. Sixty-two automated tests run continuously against our live infrastructure, identity provider, code repositories, and endpoints — checking encryption, access, logging, backups, and vulnerability management, and alerting us the moment one of them drifts.
Live control status
Our continuously monitored control status is published through our compliance platform's trust center. It isn't public yet — until it is, we'll send the current status, our security overview, and any diligence documentation on request.
Request our security overviewWhere we are on SOC 2
SOC 2 Type I readiness is in progress. We are not SOC 2 certified, and we won't say otherwise until we hold a report.
Concretely: our control set, policies, and evidence are being built and monitored against the SOC 2 Security Trust Services Criteria. No audit has been completed, and no independent auditor has issued an opinion on our controls. We're also building toward NIST SP 800-171 for customers whose contracts require it.
If your procurement process needs a firm date or a specific artifact, ask us — we'd rather tell you exactly where we are than let a badge imply something we haven't earned.
What's actually in place today
- A tamper-evident audit chain you can verify yourself. Every scan is recorded in a SHA-256 hash-chained ledger. The public verifier re-computes the chain in your own browser — you don't have to take our word that a record wasn't altered.
- Encryption in transit and at rest. All traffic is TLS-encrypted. Data at rest is stored on Azure Storage and encrypted by the platform. We do not yet add an application-layer encryption envelope on top of that — it's on the roadmap, and we'd rather say so than round up.
- Two-step verification. TOTP two-step verification is available on every account, and fleet managers can require it across their whole organization.
- Vulnerability management. Continuous dependency and code scanning across our repositories, with findings triaged and tracked to closure.
- Off-site encrypted backups, with restore drills. Backups replicate to an independent off-site provider under a retention policy. Restores are drilled rather than assumed — most recently exercised during our July 2026 infrastructure migration.
- Access control and review. Least-privilege access with a documented quarterly access review and a written deprovisioning runbook covering every system, API key, and integration credential.
- Documented incident response. A written incident response plan and a separate breach notification SOP, with defined severity levels, owners, and regulatory notification timelines.
- Data minimization by design. We collect the driver data hazmat compliance actually requires — name, CDL number, endorsement and expiry — and no more. Our privacy policy lists exactly what's held and why.
- Cyber liability insurance. Carried, including breach response support.
- A published disclosure policy. Our vulnerability disclosure policy sets out how to report an issue, what we prioritize, and our commitment not to pursue good-faith researchers.
What we don't claim
Every vendor's security page tells you what they have. This is the part that's usually missing, and it's the part worth reading.
- Not SOC 2 certified. Readiness is in progress; no audit completed, no report issued.
- Not ISO 27001 certified, not FedRAMP authorized. Neither is in progress today.
- No dedicated security team. HaulGuard AI is a small, founder-led company. That's precisely why we lean on continuous automated monitoring rather than on someone remembering to check.
- No agency endorsement. We are not affiliated with, endorsed by, or certified by DOT, PHMSA, FMCSA, or CVSA.
- Not "tamper-proof." The audit chain is tamper-evident: it makes alteration detectable. It does not make alteration impossible, and we don't market it as though it does.
Questions, or a security review to run?
Send security questionnaires, diligence requests, or vendor-review paperwork to
zackary@haulguard.ai — or use the
contact form. To report a vulnerability, follow our
vulnerability disclosure policy and put
[security] in the subject line so it doesn't get triaged with general inbound.