VelaHema

Security

How VelaHema keeps each company's operations, drivers' records and locations private.

Separate workspaces
Every record carries its company in the database, and related records must belong to the same company. The server takes the company from your signed-in session, never from the browser. Attempts to open another company's records return not found and are logged.
Roles checked on every request
Admin, dispatcher, fleet manager, compliance manager, driver, auditor and billing roles each have a fixed set of permissions enforced by the server. Drivers see only their own loads and records.
Sign-in
Passwords are hashed with scrypt. Repeated failures lock the account temporarily. Two-step sign-in with an authenticator app is required for company admins and the platform owner, with one-time recovery codes.
Sessions
Sessions use secure, HTTP-only cookies with idle and absolute timeouts and are rotated at sign-in. Changing your password signs out other devices, and you can sign out everywhere.
Requests from other sites
Changes require a per-session token and a matching origin, which blocks cross-site request forgery.
Files
Uploads are checked by content type, encrypted at rest with a key per company, and downloaded through signed links that expire in five minutes.
Payments
Card details are entered on Stripe's hosted page. VelaHema never receives card numbers. A subscription turns on only after a verified message from Stripe, never from a browser redirect.
Audit log
Sign-ins, changes, exports, reviews and support access are recorded with who, what and when. Company admins and auditors can read their company's log.
Support access
If VelaHema support needs to look at your workspace, access is read-only, time-limited, requires a written reason, and appears in your audit log.
Location privacy
Drivers turn location sharing on themselves and can turn it off. Only dispatchers, fleet managers and admins of the same company can see it. Location history is deleted after a retention period.

No system is free of risk, and VelaHema does not claim any certification. To report a security issue, use the contact form and choose security in the message.