Security
Built for operational trust.
FreightSurf is engineered with security at every layer — from how we access your Gmail inbox to how we store your carrier intelligence. This page explains exactly what we do, and what we never do, with your data.
Gmail Permission Transparency
Exactly what FreightSurf can and cannot do with your Gmail.
We believe you should understand precisely what permissions FreightSurf requests and why. No surprises.
What FreightSurf Does
- Reads your Gmail inbox to identify inbound carrier emails using the
gmail.readonlyscope. - Temporarily processes all inbox messages to classify carrier vs. non-carrier communications.
- Extracts structured freight intelligence from carrier emails (MC numbers, lanes, rates, equipment).
- Stores carrier intelligence in your encrypted FreightSurf account database.
- Sends outbound emails on your behalf via
gmail.sendscope — only when you explicitly compose and authorize an outbound reply within the platform.
What FreightSurf Never Does
- Never stores the content of non-carrier emails. Non-carrier messages are identified and immediately discarded.
- Never modifies, archives, moves, labels, or deletes any email in your inbox.
- Never accesses your Gmail contacts, calendar, Drive, or any Google service beyond your inbox.
- Never sends emails autonomously — outbound emails require your explicit authorization every time.
- Never shares or sells your Gmail data to third parties for their independent use.
- Never uses your Gmail data for advertising or third-party marketing.
- Never uses Gmail data to train general-purpose AI models.
You can review and revoke FreightSurf's Gmail access at any time at myaccount.google.com/permissions. FreightSurf's use of Google APIs complies with the Google API Services User Data Policy, including Limited Use requirements.
Infrastructure
Security at every layer.
Data Encryption
All data transmitted to and from FreightSurf is encrypted in transit using TLS 1.3. All data stored at rest — including carrier intelligence, account data, and extracted freight records — is encrypted using AES-256.
- TLS 1.3 for all data in transit
- AES-256 encryption at rest
- Encrypted database storage
- Encrypted backup systems
Infrastructure Security
FreightSurf runs on enterprise-grade cloud infrastructure with security controls designed for high-availability operational platforms. We apply security-first architectural practices across all system components.
- Enterprise cloud hosting with isolated compute environments
- Continuous infrastructure monitoring and anomaly detection
- Automatic failover and redundancy systems
- Regular security reviews of infrastructure configuration
- Network-level isolation between customer data environments
Authentication & Access Control
FreightSurf enforces strict access control across all system layers. Production system access is restricted to a minimal set of authorized engineers using least-privilege principles.
- OAuth 2.0 for Gmail integration — no password storage
- Secure session token management with automatic expiration
- Least-privilege access model for all internal systems
- Role-based access controls on Team and Enterprise plans
- Database access restricted and logged per access event
Monitoring & Audit Logging
FreightSurf maintains comprehensive audit logs of platform activity, including Gmail sync events, carrier verification queries, and user actions within the platform. These logs support transparency and incident response.
- Platform activity logs retained per plan tier
- FMCSA verification queries logged and auditable
- Gmail sync events logged with timestamps
- Outbound email actions recorded with user authorization timestamps
- Security event alerting for anomalous access patterns
AI Data Handling
FreightSurf uses OpenAI's API for natural language processing features. Carrier email content submitted to OpenAI for classification is governed by an enterprise API agreement that prohibits use of your data to train or improve OpenAI's models.
- OpenAI API-only usage — no shared model training
- Customer data not used to improve any third-party AI system
- Encrypted transmission to AI processing endpoints
- AI outputs are informational — not stored as ground truth
- Minimal data submission principle — only necessary context sent
Carrier Data Protection
Your carrier intelligence database — the operational core of your FreightSurf account — is isolated, encrypted, and accessible only to your authorized team members.
- Carrier data stored in isolated per-account namespaces
- FMCSA data sourced from official government APIs only
- No cross-account data sharing or aggregated profiling
- Carrier data exportable on request in standard formats
- Data deleted within 30 days of account termination
Honest Security Posture
What we don't overclaim.
FreightSurf is built with security-first architecture and enterprise-grade infrastructure practices. We believe in honest security communication.
We do not claim certifications we have not completed. We actively maintain a strong security posture and will update this page as our security program matures.
Security-first architecture
Enterprise-grade cloud infrastructure
AES-256 + TLS 1.3 encryption
Least-privilege access model
SOC 2 Type II certified
Not yet certified. On our roadmap.
ISO 27001 certified
Not currently certified.
HIPAA compliant
Not applicable — no health data processed.
Account security best practices.
The security of your brokerage data is a shared responsibility. Here is what we recommend.
Use a dedicated Gmail account
For highest security isolation, connect a dedicated brokerage Gmail account to FreightSurf rather than a personal or administrator inbox.
Review connected apps regularly
Periodically review which apps have access to your Google account at myaccount.google.com/permissions. Revoke any access you no longer need.
Report suspicious activity
If you notice unusual platform activity or suspect unauthorized access to your FreightSurf account, contact support@freightsurf.com immediately.
Have a security question?
Our team is available to answer security questions before you connect your inbox. For vulnerability disclosures, please contact us directly.
For responsible disclosure of security vulnerabilities, please email support@freightsurf.com with subject line “Security Disclosure”.