HomeDocsSecurity & roles

Documentation

Everything you need to run your fleet on FreightCMD.

Security & roles

Tenant isolation

Every workspace is a separate tenant. FreightCMD enforces row-level security on every table — no query can ever cross workspace boundaries, even if you have access to another tenant.

Roles

  • CEO / Owner — full control, billing, invites.
  • Admin — manage staff, vehicles, clients and finance.
  • Dispatcher — create and assign trips, monitor the fleet.
  • Accountant — view invoices and payments only.
  • Driver — see assigned trips and update status from the mobile app.
  • Client — self-serve portal for their own trips and invoices.

Authentication

Email and password by default. Magic links and OAuth providers can be enabled per workspace. All sessions are HTTPS-only with refresh-token rotation.

Data residency

Production data is hosted in the EU by default with a Singapore region available for Sri Lankan customers on the Enterprise plan. Daily encrypted backups are retained for 30 days.

Reporting a vulnerability

Please email security@freightcmd.app. We respond within one business day and credit responsible disclosures.