Security
How VelaHema keeps each company's operations, drivers' records and locations private.
- Separate workspaces
- Every record carries its company in the database, and related records must belong to the same company. The server takes the company from your signed-in session, never from the browser. Attempts to open another company's records return not found and are logged.
- Roles checked on every request
- Admin, dispatcher, fleet manager, compliance manager, driver, auditor and billing roles each have a fixed set of permissions enforced by the server. Drivers see only their own loads and records.
- Sign-in
- Passwords are hashed with scrypt. Repeated failures lock the account temporarily. Two-step sign-in with an authenticator app is required for company admins and the platform owner, with one-time recovery codes.
- Sessions
- Sessions use secure, HTTP-only cookies with idle and absolute timeouts and are rotated at sign-in. Changing your password signs out other devices, and you can sign out everywhere.
- Requests from other sites
- Changes require a per-session token and a matching origin, which blocks cross-site request forgery.
- Files
- Uploads are checked by content type, encrypted at rest with a key per company, and downloaded through signed links that expire in five minutes.
- Payments
- Card details are entered on Stripe's hosted page. VelaHema never receives card numbers. A subscription turns on only after a verified message from Stripe, never from a browser redirect.
- Audit log
- Sign-ins, changes, exports, reviews and support access are recorded with who, what and when. Company admins and auditors can read their company's log.
- Support access
- If VelaHema support needs to look at your workspace, access is read-only, time-limited, requires a written reason, and appears in your audit log.
- Location privacy
- Drivers turn location sharing on themselves and can turn it off. Only dispatchers, fleet managers and admins of the same company can see it. Location history is deleted after a retention period.
No system is free of risk, and VelaHema does not claim any certification. To report a security issue, use the contact form and choose security in the message.