DOCUMENT NOTICE
PRODUCTION NOTICE: This exact version was approved for production and made effective on August 1, 2026 by Jaime E. Fuentes II under TT-LGL-000P, TT-LGL-000Q, and TT-LGL-000R. It has not been reviewed or approved by an attorney and does not represent a certification, audit opinion, penetration test, or guarantee. This Overview is active for TruckerTech-controlled surfaces that link to it. Claims are limited to the current scope stated here and will be updated as additional provider, control, testing, and operational evidence becomes available.
TT-SEC-010
Security Program
TruckerTech uses a risk-based security approach for a multi-role freight trust and orchestration platform. The program is designed to use administrative, technical, and organizational measures appropriate to the services, data, providers, and stage of operation. No security program can eliminate every risk, and this Overview does not guarantee that every threat, error, misuse, or incident will be prevented.
TT-SEC-010
Identity and Access
TruckerTech uses authenticated accounts and designs governed access around server-resolved organization, role, object, action, and workflow context. Access is intended to follow least-privilege principles, and organizations are responsible for maintaining accurate administrators, permissions, and authorized users. External reliance on TruckerTech single sign-on or identity assertions is not included unless separately released and documented.
TT-SEC-010
Data Protection
TruckerTech’s architecture uses data-minimization and access-separation principles by organization, role, purpose, object, field, action, and workflow where applicable. Hosting and data-platform providers maintain their own physical, infrastructure, storage, and encryption controls under their service terms and configurations. Biometric, liveness, and Live Acceptance processing remains disabled for the base launch.
TT-SEC-010
Application and Infrastructure Security
TruckerTech’s secure-development practices are designed to include controlled source access, code review, dependency and security checks, secret protection, environment separation, logging minimization, attributable audit evidence for specified material actions, and controlled change and release processes. Coverage and maturity may vary by component and release stage. TruckerTech does not represent that every activity is continuously monitored or that every defect is detected before release.
TT-SEC-010
Vendor and Integration Security
Providers and Ecosystem Partners may be evaluated based on service criticality and data access. Contracts should address confidentiality, security controls, incident notice, subprocessors, retention, deletion, permitted use, audit evidence, and termination. Connected accounts and APIs should use bounded scopes, credential protection, rate limits, logging, and revocation.
TT-SEC-010
Identity Assurance
Identity-document, selfie, biometric, face-comparison, liveness, and Live Acceptance functions are not included in the base launch. Any later activation requires a separately governed identity-assurance program, selected provider, purpose-specific notice and consent, retention and deletion controls, security testing, and an explicit Founder activation decision.
TT-SEC-010
Monitoring and Incident Response
TruckerTech maintains or develops procedures for reporting, triage, containment, investigation, evidence preservation, remediation, notification decisions, communications, and lessons learned. Incident handling depends on the nature of the event, affected systems and people, provider involvement, and applicable law. No fixed response, remediation, or notification time is promised unless stated in a signed agreement or required by law.
TT-SEC-010
Business Continuity
TruckerTech uses provider and internal processes intended to support backup, restoration, dependency management, escalation, continuity, and recovery as applicable to the service. No recovery-time objective, recovery-point objective, failover, data-loss, uptime, or service-credit commitment is made in this Overview. Any numeric service-level commitment must appear in a separate signed agreement.
TT-SEC-010
Customer Responsibilities
Users and organizations must protect credentials, configure permissions responsibly, maintain accurate administrators, secure devices and connected systems, promptly remove access, review unusual activity, and report suspected compromise.
TT-SEC-010
Vulnerability Reporting
Security concerns may be reported to security@truckertech.com. Initial reports should avoid passwords, payment credentials, identity documents, personal information, exploit payloads, or other sensitive evidence. TruckerTech may provide a separate secure-transfer method after initial contact. The Vulnerability Disclosure Policy describes the rules for good-faith research and coordinated reporting.
TT-SEC-010
Assurance and Transparency
TruckerTech will not claim certifications, penetration-test results, control maturity, uptime, encryption details, or compliance status that has not been verified. Security documentation will be updated as controls mature.