Designed for confidential insurance workflows
Fleetr is built for Canadian insurance brokerages that handle confidential customer information. Production data is hosted in Canada, access is agency-scoped, activity is logged, and uploaded policy documents are processed on a short-lived basis.
Fleetr is an independent software provider and is not affiliated with, endorsed by, or operated by the Insurance Corporation of British Columbia (ICBC).
Canadian production hosting
Production application, database and uploaded insurance-document processing occur on Canadian infrastructure. Limited business-contact and operational email information may be processed outside Canada; uploaded insurance documents are not sent through that email service.
Encryption
- The production service is provided over HTTPS using TLS 1.2 or higher.
- Session cookies are marked Secure, HttpOnly, and SameSite=Lax in production.
- Sensitive client-directory fields (names, addresses, fleet numbers) are encrypted at rest with AES-256.
- Broker stamps and signatures are stored as encrypted files under the user profile.
- Passwords are stored as one-way PBKDF2-SHA256 hashes, not plain text.
- Uploaded and generated insurance documents are encrypted in transit and at rest while temporarily processed and are deleted upon download where possible, or within approximately 30 minutes.
Access control and agency isolation
- Brokers can access clients and documents only for agencies they are assigned to. Logins are for named individuals and are not intended to be shared.
- Role-based permissions separate broker, administrative, and superuser functions on a least-privilege basis.
- Fleetr supports TOTP multi-factor authentication with authenticator apps. MFA is mandatory for Fleetr administrative and superuser accounts. For other user accounts, MFA is enforceable by the agency. When MFA is in use, a password check creates only a pending challenge; the user session starts after the authenticator code is verified. Enrollment issues one-time recovery codes.
- Trusted-device tokens are opaque, stored hashed server-side, and expire after 30 days for regular users or 7 days for admin roles.
- Processed PDF downloads require login and are tied to the user’s processing job — not public filenames.
Retention
We separate short-lived operational files from longer-lived account records:
| Type | Examples | Typical retention |
|---|---|---|
| Ephemeral operational | Upload merges, stamped outputs for download | Until you download, or about 30 minutes |
| Operational persistent | Client directory, stamps, signatures | Until your agency removes them |
| Billing and audit | Usage counts, invoices, activity log | As needed for operations, accounting, and security |
Logging and auditability
Fleetr records significant account, billing, document-processing, and privileged administrative events (who did what and when) for security, support, and compliance. Administrative access is restricted to authorized Fleetr personnel with a legitimate operational, support, security, or compliance need. Production administrative accounts are named individuals, MFA is mandatory for those accounts, access is least-privilege, and shared admin credentials are not used.
Incident handling
Fleetr maintains an incident-response process. We investigate suspected privacy or security incidents, promptly inform affected customers as required by contract, and notify regulators and individuals where legally required.
Service providers
Fleetr uses service providers to operate the service. They receive only the information needed to perform their functions and are subject to confidentiality and data-protection obligations:
- DigitalOcean — production hosting in Canada.
- Email delivery — demo requests, account notices, and similar operational messages; may involve processing outside Canada. Uploaded insurance documents are not sent by email.
Contact the Privacy Officer for a current description of these providers.
Privacy governance
A Privacy Officer is responsible for Fleetr’s privacy practices. Practices are designed around British Columbia’s Personal Information Protection Act (PIPA), and PIPEDA where it applies. Fleetr does not currently hold SOC 2 or ISO 27001 certification, and we do not describe the product as ICBC-approved or FIPPA-compliant.
Questions, incidents, and responsible disclosure
Privacy Officer
Rodigan Labs Ltd. o/a Fleetr
Victoria, British Columbia, Canada
jordan@fleetr.ca
Use the same address to report a suspected privacy incident or a security vulnerability. Please include enough detail for us to investigate and avoid accessing or disrupting other customers’ data.