Published by Rigmatix. Describes controls in place today — not a third-party audit opinion.
All traffic between your browser and Rigmatix is served over HTTPS/TLS. Our API and file endpoints reject plaintext HTTP.
Every operational table (loads, drivers, invoices, settlements, documents, fuel, IFTA) enforces row-level access rules in the database itself, scoped to your company. Isolation does not depend on application code remembering to filter.
Permissions are derived from server-side roles (owner, admin, dispatcher, driver) stored separately from user profiles, so a user cannot elevate their own privileges. Drivers can update only their own live location; privileged fields are rejected by the database.
Changes to sensitive records — user roles, profiles, subscriptions, invoices, settlements, drivers, documents, branding, invite codes — are recorded automatically with the acting user, timestamp, and which fields changed. Audit records are read-only and cannot be edited or deleted from the application.
New and changed passwords are checked against known breached-password corpora and rejected if compromised. Email addresses must be confirmed before an account becomes active. Anonymous sign-up is disabled.
Card payments are handled through hosted checkout. Rigmatix never receives or stores full card numbers.
Rigmatix does not currently hold a SOC 2 report or ISO/IEC 27001 certificate, and we do not claim otherwise. The controls described on this page are our own practices.
Email security@gorigmatix.com with the affected URL or endpoint, reproduction steps, and impact. We aim to acknowledge reports within 3 business days. Please do not access, modify, or exfiltrate data belonging to other customers, and give us reasonable time to remediate before public disclosure.