Security
DUMO LOGISTIC holds your drivers’ locations and your customers’ details, so we keep the setup simple, standard and strict. This is exactly what is in place today.
Signing in
- Human check on every sign-in form
- Sign-in, sign-up, password reset and account setup are protected by a human check (Cloudflare Turnstile), enforced by the sign-in server as well, to stop automated password guessing and fake accounts.
- Two-step login
- Every account can turn on two-step login with an authenticator app. It is always required for the platform owner’s area.
- Passwords
- Passwords are hashed by the authentication service and are never stored in plain text.
Your company’s data
- Separated per company
- Every database table uses row-level security, so each company only ever sees its own drivers, vehicles, deliveries and customers. An account with two-step login sees nothing until its code is entered.
- Stored in Singapore
- Data is stored with Supabase in Singapore (ap-southeast-1), encrypted in transit (HTTPS only, HSTS) and at rest.
- Daily backups
- The database is backed up every day.
- Customer tracking links
- Tracking links are long random codes that show only that one delivery, and they stop working 30 days after the delivery is completed or cancelled.
The website and the code
- Hosting and traffic protection
- The app runs on Vercel with automatic DDoS protection, plus firewall rate limits on the app’s server endpoints.
- Security headers and secrets
- Security headers block clickjacking and content sniffing. Secret keys live only on the server, never in the browser.
- Dependency updates
- Automated alerts and fixes for security issues in the software libraries the code uses (GitHub Dependabot).
Found a security problem?
Please tell us privately through our Contact page and don’t share it publicly until it’s fixed. See also our Privacy Policy.
