ISO 27001 is the management system. These are the specific architectural
properties that make enterprise security reviews pass.
Multi-tenant isolation
Customer data is partitioned per tenant. Rule bundles, orders, vehicles, and routes are not reachable across tenant boundaries. The enforcement mechanism is implemented per our ISO 27001 ISMS scope; details available under DPA on request.
OAuth2 and JWT authentication
Standards-based authentication. Access tokens are short-lived; scoping, revocation, and rotation are implemented per our ISO 27001 ISMS scope; details available under DPA on request.
TLS in transit, encryption at rest
All traffic is TLS 1.2 or higher. Data at rest is encrypted on the storage layer. Key management is implemented per our ISO 27001 ISMS scope; details available under DPA on request.
Audit logs
State-changing API calls are recorded. Read APIs are logged. Log retention, format, rate controls, and access controls are implemented per our ISO 27001 ISMS scope; details available under DPA on request.