Security

Last updated 2 October 2026

Routy is operated by Routy LLC, Glendale, Arizona. Carriers trust us with their loads, documents, settlements, and driver details. This page explains how we protect them.


How your data is protected

Encrypted in transit and at rest. Every connection to Routy uses HTTPS — plain HTTP is redirected, and browsers are told to always use HTTPS. Stored data and documents are encrypted at rest by our database and storage provider.

Separated by carrier. Every record belongs to one carrier, and Routy only reads and writes the signed-in user's own carrier — an automated check enforces this on every change to our code. Membership is re-checked as people move through the dashboard, so a removed team member loses access within about 30 seconds. Routy staff can see carrier data when they need it to run and support the service, through a separate admin console that requires an emailed one-time code to sign in.

Tax IDs get extra protection. Social Security numbers and EINs are encrypted (AES-256-GCM) before they are stored, with the key kept outside the database. Routy shows only the last four digits, except in the year-end company tax report (on screen and in its PDF and Excel downloads), where only the carrier's Owner sees the full number.

Signed-in access only. Every dashboard page requires a signed-in session, checked before any page code runs. Drivers and dispatchers using the Telegram mini-app are verified through Telegram's signed login data.

AI document reading. Rate confirmations, receipts, and voice notes are read by AI providers (Anthropic and OpenAI) whose terms for business use do not allow training on your content.


Service providers

These companies run parts of Routy for us. They may only use carrier data to provide that service.

  • Vercel — application hosting
  • Supabase — database and document storage
  • Twilio — the phone line and verification codes (on calls, speech recognition is by Deepgram and the voice by Google, through Twilio)
  • Telegram — driver and dispatcher messaging
  • Google — email for carriers who connect Gmail; maps, routing, and address lookup
  • Resend — account and billing email
  • Mapbox — maps
  • Anthropic — AI document reading
  • OpenAI — voice-note transcription and truck diagnostics
  • Serper — business and place search (finding a shop or a facility)
  • Cloudflare — bot protection on sign-up

ELD and telematics providers (such as Samsara and Motive) are connected by the carrier and send us truck location and status data. A carrier can also connect its own Slack for notifications. Public records — FMCSA carrier lookups and National Weather Service alerts for a truck's location — come from government services.


If something goes wrong

If a security incident affects a carrier's data, we will tell the affected carriers promptly.


Reporting a security issue

Email support@routytms.com with "Security" in the subject line. Please include what you found and how to reproduce it, and give us a reasonable time to fix it before sharing it publicly. Our security.txt lists the same contact.


Where we are today

Routy is in early access. We have not yet completed a third-party security audit such as SOC 2. When we do, it will be listed on this page.

See also our Privacy Policy.