Security & data posture

Built like the operator
would want to audit it.

We're not a fortune-500 with a 200-page security PDF, and we won't pretend to be. We're an independent UK platform, hosting your data on UK boxes, with the posture an experienced operator (or their accountant) would expect on the first call.

UK-hostedTLS 1.3Stripe ConnectGDPR-by-defaultTfL-awareDaily backupRow-level scopeOne-button export

Hosting

UK-hosted by default.

Your tenant data — bookings, customers, drivers, photos — lives on infrastructure provisioned in UK data centres. No US-shaped cloud detour.

  • London-region VPS, redundant SSDs
  • Daily off-site snapshot retained 7 days
  • Network-isolated database, no public ingress
  • TLS 1.3 with HSTS preloaded on every domain

Data

Encrypted, scoped, portable.

Multi-tenant Postgres with per-agency row scoping. Every read goes through a tenant filter; no cross-tenant joins are possible from application code.

  • Postgres column encryption for tokens (Stripe / Xero / WhatsApp)
  • Row-level scoping by `agencyId` enforced at the Drizzle layer
  • Audit log on every state-changing booking action
  • Fleet tier: export a full PHP + MySQL archive of your data, any time

Money

Stripe Connect — your money, your account.

We never custody operator funds. Stripe Connect routes every captured payment directly to your own Stripe account; we receive a webhook, not your settled cash.

  • SCA / 3DS handled natively in the booking widget
  • Card held at quote, captured on completion (or auto-released)
  • GoCardless Direct Debit for corporate monthly accounts
  • VAT codes mapped to TOMS-2026 logic for Xero / FreeAgent push

Compliance

GDPR-by-default, TfL-aware.

Built UK-first. Driver and customer PII is minimised, retention is configurable, and audit packs are one button.

  • Per-agency DPA available; UK-only sub-processors by default
  • Customer right-to-be-forgotten endpoint exposed in the dashboard
  • Driver compliance grid: PHV badge, DBS, SERU, English, MOT, plate, insurance
  • One-button TfL audit PDF — the document no other platform actually ships

Identity

Better Auth · shared session · scoped roles.

Identity sits in a hardened Better Auth deployment with the session cookie scoped per product. Roles are scoped per agency: owner, dispatcher, accountant, driver.

  • Session cookie scoped per host (HttpOnly, Secure, SameSite=Lax)
  • Magic-link sign-in for drivers — no phone OS lock-in
  • Per-route platform-admin guard; agency-admin scoped to tenant
  • MCP API keys revocable per agency; off by default

Operations

Observable, recoverable, reviewable.

Every container restart, migration, backup and deploy is logged. Container resource caps stop one runaway tenant dragging the host down.

  • Per-service mem_limit + pids_limit on every container
  • Healthchecks on every public surface (nc-z probes; CPU-steal tolerant)
  • Backup script runs nightly, restore script tested monthly
  • Deploy guard refuses to ship when load > 4 or free RAM < 1 GB

Need the paperwork?

DPA. Sub-processor list.
SLA on the way.

We're happy to share a DPA, our sub-processor list and a draft SLA on request. If your client requires SOC 2 or ISO 27001 we'll be straight with you about where we are on that road.