Workspace isolation
Each signup receives an organization-scoped workspace. Authenticated records, loads, payments, documents, and exports are filtered to that organization.
Small carriers should be able to ask direct questions about their operational data. This page describes the current application controls without pretending that a hosting setting or a checklist replaces an independent security review.
Each signup receives an organization-scoped workspace. Authenticated records, loads, payments, documents, and exports are filtered to that organization.
CarrierOS sends subscription checkout and customer-portal payment details to Stripe. The application does not ask for or store card or bank credentials.
Important changes are recorded in the workspace audit trail, and administrators can download company data plus filtered load CSV exports.
RateCon and delivery-document workflows require configured private storage and malware scanning. Audit uploads are processed for structured findings and raw files are not retained.
Backups: configure daily logical backups, off-host copies, and a tested restore process.
Secrets: use host-managed environment variables for session, Stripe, SMTP, storage, and scanner credentials.
Access: use strong passwords, least-privilege staff accounts, and a verified support mailbox.
Review: have qualified legal and security professionals review the policies and sensitive-data workflow before a high-volume launch.
David Bryant is available directly to discuss setup, data boundaries, and what CarrierOS should or should not replace in your operation.