Skip to content
Trust and security

Secure by design. Auditable by default.

This page is written for the person who has to fill in a form about us. Everything below is a working control today. If you need a security questionnaire or a VPAT completed, ask and we will do it.

Your data

Lives in Australia
Hosted onshore, end to end. Data sovereignty is a design decision here, not a deployment option.
Isolated at the core
Every organisation’s data is walled off inside the database itself, not just in application code. Crossing that wall is structurally impossible, no matter who is signed in, and we test that it is on every build.
Yours to take
Export everything, any time, in open formats, and leave from your own account screen without asking us. Portability is written into the contract, because a platform you cannot leave is a platform you cannot trust.

Accountability

Fully auditable, always
Every action of consequence writes a permanent record the moment it happens. An audit or FOI request is answered in minutes from the record, never reconstructed by hand months later.
Access that fits the person
Everyone signs in to exactly what their job needs and nothing more. A client sees its fleet, a driver sees their vehicle, a workshop sees the job in front of it.
Two people for the big moves
Sensitive actions need a second person to approve them. Emergency access is requested, approved by someone else, time capped, single use, and stamped onto every record it touches. There are no quiet superpowers, including ours.

The record itself

Append only, by construction
Entries are added, never overwritten. A correction is a new entry that says what changed and who changed it, so the history of the history survives too.
Verifiable, not just trusted
Documents are content hashed. Snapshots are signed and stored byte for byte, so a record handed to an auditor can be checked rather than believed.
Honest about its gaps
Where evidence is partial the platform says so on the screen and labels the figure a floor rather than a total. We would rather show you a smaller number you can defend.

Privacy

A record of the vehicle
The passport describes an asset and the businesses that attested to work on it. It is not a record of who was driving, it carries no journey history, and it does not name the people inside your organisation who approved, authorised or requested anything.
Your accountability trail stays yours
Who approved what, who signed off which spend, and the commercial terms that applied are recorded in full for your own audit and governance. They sit inside your organisation and do not cross a boundary with the vehicle. The next owner learns what was done to the car, not who decided it or what rate you paid.
Only what the job needs
Each party sees the part of the record their work requires and no more. A workshop sees the job in front of it. A trade buyer sees the asset and its service history, and nothing about the people around it.

The assistant

It can only do what it is allowed to say
Ask Fleeter answers from your own record, in plain words. It works from a closed list of named actions with no general access to the database, the API or the internet, and it borrows the identity of the person asking, so it can never see or do more than they can.
Every change is a plan you confirm
The assistant proposes; a person disposes. Anything that would change the record is written out as a visible plan, confirmed by the same person who asked, and it expires unused in fifteen minutes. The audit line says the action came via the assistant.
Off until you turn it on
Every organisation starts with the assistant switched off. Someone with the authority to change your configuration turns it on, read only first if you prefer, and the processing policy, retention and budgets are enforced before anything leaves your tenant.

Identity and assurance

Your sign on, not another password
Fleeter connects to your corporate identity provider, so your people sign in with the same enterprise single sign on and access controls they already use everywhere else.
Accessible to the public sector bar
Built to WCAG 2.2 AA and aligned to the Australian Digital Service Standard, the same bar our government customers are audited against. VPAT available on request.
Engineered for certification
The target is ISO 27001. The controls it audits are in the architecture rather than bolted on, and the monthly evidence bundles an auditor replays have accumulated since launch; the certification audit follows twelve months of operating evidence. Until then we say not yet certified, and the evidence pack is available to procurement today.

Need our security summary as a leave behind for procurement? We will send the pack: controls, residency, accessibility statement and certification status in one document.

Send us the questionnaire.

We would rather answer it now than at the end of a procurement. Tell us what your reviewers need and we will complete it properly.