FREIGHTSHIELDBrokerage & Carrier Verification
Security

Security controls, stated plainly.

FreightShield holds carrier identity documents, driver location, and payment instructions. These are the controls protecting them, and the guarantees we are willing to put in writing.

Tenant isolation

Every business-owned record carries an immutable organization id and is protected by row-level security in the database itself, not only in application code. Cross-tenant access attempts are tested in CI.

Authentication and step-up

Passkeys and TOTP multi-factor, with re-authentication required before privileged actions such as changing payment destinations, overriding a risk decision, or releasing funds.

Least-privilege location access

Precise driver position is visible only to configured roles, and only inside active load windows. Outside those windows the location is coarsened or withheld entirely.

Append-only audit

Carrier, load, incident, document, and payment status cannot change without an audit event. The ledger is hash-chained, insert-only, and has no update or delete grant.

Encryption and key handling

TLS in transit, AES-256 at rest, provider tokens encrypted at the column level, and secrets excluded from logs by structured redaction rather than convention.

Recoverability

Point-in-time recovery, object versioning, and rehearsed restore drills. Migrations are expand-and-contract so a rollback never requires destroying data.

On automated decisions

A single data discrepancy is never treated as proof of fraud. Signals accumulate into a score with a stated confidence, every automated action carries evidence and an expiration, and a human can review and override any decision with a recorded reason. Carriers can appeal, and appeals are answered.

See it against your own lanes.

We will run your real carriers through clearance during the call.