✓Per-operator data isolation
Row-level security is enforced in the database itself, not just in the interface — there is no route by which one operator can read another operator’s bookings, customers or drivers.
✓Encrypted sensitive fields
Driver bank details and tax references are encrypted at rest and can only be read back through an owner-only, audited path.
✓Reliable, backed-up hosting
Your data sits on managed infrastructure with daily backups, and we can host it in the region you need.
✓Daily backups
Bookings, customers, drivers and financial records are backed up every day.
✓HTTPS everywhere
Every app is served over HTTPS only, with strict transport security, a restrictive content security policy and clickjacking protection.
✓Role-based access
Owner, dispatcher and viewer roles are enforced at the database level, so a read-only account genuinely cannot write — even outside the interface.
In more detail
How separation between operators works
Every row of data carries the operator it belongs to, and PostgreSQL row-level security filters every query against the identity of whoever is logged in. It is enforced by the database, not by the interface — so even a request made outside the apps entirely still cannot reach another operator’s records.
Where secrets live
Your Stripe, Twilio, SendGrid and Maps keys are encrypted before they are stored, and can only be decrypted by the server-side function that needs to use them. They are never sent to a browser, never written into an app bundle, and only an owner account can enter or reveal them.
Driver personal data
Bank account numbers, sort codes and UTR numbers are encrypted at rest with a key held outside the database, and reading them back is an owner-only action. Deleting a driver removes their login and their uploaded documents from file storage as well as their record.
Passwords and access
Passwords are hashed by our authentication provider and never stored in a form we can read. Accounts are owner, dispatcher or viewer, and those roles are enforced in the database — a viewer account genuinely cannot write, not merely cannot see the buttons.
In transit and in the browser
Every app is served over HTTPS only, with HTTP Strict Transport Security, a content security policy restricting what the page may load, MIME-sniffing protection and framing denied so the apps cannot be embedded and clickjacked.
Backups and deletion
The database is backed up daily. When an operator closes their account, access ends immediately and their data is fully purged — records, uploaded files and logins — after a short recovery window in case the closure was a mistake.
What we don’t claim
We are not ISO 27001 or SOC 2 certified, and we are not going to imply otherwise. Almighty Dispatch is built by a small company on well-established managed infrastructure, and the protections above are real and specific — but they are engineering practice, not an audited certification. If your own customers require a certified supplier, tell us early and we will be straight with you about where we stand.
Found something that looks wrong? Email info@almightydispatch.com with “Security” in the subject line and it goes straight to someone technical. We will not send a lawyer after anyone who reports a genuine problem responsibly.