TRUST & SECURITY

Enterprise Security & Platform Governance

How FleetQore protects operator assets, customer records, and financial transactions across the GCC through multi-tenant isolation, cryptographic audit trails, and zero-trust controls.

256-Bit
AES-GCM Encryption Standard
Zero Trust
Role-Based Access Control (RBAC)
Immutable
DuckDB Cryptographic Audit Logs
GCC Native
KSA & Qatar Regulatory Alignment
SECTION 01

Our Approach to Enterprise Security

FleetQore is architected from the ground up as a defense-in-depth, multi-tenant enterprise operating system. Security is not an afterthought or an add-on module—it is built into every layer of our software architecture, from edge API gateways down to database query isolation.

We enforce strict tenant segregation across all software surfaces. When operating across multiple branches or franchise networks, partner data is partitioned at the database schema and application layer, ensuring zero cross-tenant data leakage or unauthorized access.

  • Multi-tenant logical isolation preventing cross-operator data leakage
  • Continuous automated vulnerability scanning across all API surfaces and application containers
  • Zero-trust network architecture with mutual TLS between microservices
  • Third-party penetration testing conducted annually by accredited cybersecurity auditors
Security Policy Directive: FleetQore engineers never access customer or operational fleet records in production environments without documented, time-bounded supervisor authorization and an active customer support ticket.
SECTION 02

Data Protection & Encryption Standards

All operational fleet records, customer personal data, telemetry streams, and transaction entries are encrypted both in transit and at rest using industry-recognized cryptographic standards.

Communications between customer mobile apps, driver field devices, branch dispatch consoles, and our cloud backbone occur exclusively over TLS 1.3 with strict HTTP Strict Transport Security (HSTS) and modern cipher suites.

  • AES-256-GCM encryption for all database records, customer KYC documents, and file storage at rest
  • TLS 1.3 enforcement with automated certificate management and strict cipher pinning
  • Hardware Security Module (HSM) key management with automated annual cryptographic key rotation
  • Automated daily encrypted snapshot backups with multi-region redundancy and verified restoration testing
SECTION 03

Role-Based Access Control (RBAC) & Authentication

Access to FleetQore operational surfaces is governed by the principle of least privilege. Organizations define custom permission tiers to match their exact operational hierarchy, ensuring staff only access the tools and data necessary for their duties.

Executive HQ administrators can configure multi-factor authentication (MFA) requirements across all staff accounts, establish session timeout policies, and instantly revoke credentials for departed employees from a centralized control panel.

  • Fine-grained permission matrices for HQ Executives, Branch Dispatchers, Counter Clerks, and Mobile Drivers
  • Mandatory Multi-Factor Authentication (MFA) support via authenticator apps (TOTP) and SMS verification
  • Single Sign-On (SSO) integration via SAML 2.0 and OIDC for enterprise holding groups
  • Instant network-wide credential revocation and global kill switches for compromised staff devices
SECTION 04

Immutable Cryptographic DuckDB Audit Trails

Operational integrity in car rental and commercial fleet management requires complete accountability. FleetQore incorporates an immutable, append-only DuckDB audit backbone that cryptographically logs every high-impact operational and financial event.

When a staff member overrides a vehicle rental rate, cancels an active reservation, modifies vehicle inspection records, or executes an inter-branch transfer, the system creates an immutable log containing the timestamp, user ID, IP address, device fingerprint, and pre/post-change state values.

  • Cryptographically verified append-only audit trail preventing internal tampering or record deletion
  • Comprehensive logging for rate overrides, security deposit refunds, vehicle handovers, and manual dispatch assignments
  • Real-time automated supervisory alerts when override frequencies exceed standard branch thresholds
  • Exportable audit reports formatted for external financial auditors and regulatory inspection authorities
SECTION 05

Infrastructure Resilience & Regional Data Sovereignty

FleetQore deploys on tier-4 enterprise cloud infrastructure designed to ensure maximum availability, fault tolerance, and localized regulatory compliance.

To align with Saudi Arabia’s National Data Management Office (NDMO) policies and Qatar’s National Cyber Security Agency (NCSA) mandates, FleetQore supports localized GCC data residency options to keep operational records within host national borders.

  • 99.9% uptime Service Level Agreement (SLA) with multi-availability-zone redundancy
  • Localized data residency options in Saudi Arabia and Qatar compliant with regional data sovereignty mandates
  • DDoS mitigation and web application firewall (WAF) filtering millions of malicious requests at the edge
  • Automated disaster recovery protocols with recovery point objective (RPO) < 5 minutes and recovery time objective (RTO) < 15 minutes
SECTION 06

Responsible Vulnerability Disclosure

We welcome constructive feedback and responsible disclosure reports from security researchers, ethical hackers, and enterprise client audit teams. If you discover a potential vulnerability within any FleetQore platform surface, please notify our security response team immediately.

We commit to acknowledging all submissions within 24 hours, providing an initial technical assessment within 72 hours, and not taking legal action against researchers who adhere to responsible disclosure principles.

  • Dedicated reporting channel monitored 24/7 by our security engineering on-call rotation
  • Rapid triage, remediation scheduling, and transparent verification communication
  • Coordination on public disclosure timing following complete deployment of verified security patches
To report a security finding or vulnerability, please email security@fleetqore.com with a technical summary, reproduction steps, and any relevant proof-of-concept logs.
ENTERPRISE TRUST

Built for enterprise security, scale & governance

Schedule a dedicated session with our solutions architects to review our multi-tenant data isolation, cryptographic DuckDB audit trails, and localized GCC compliance models.