Security & data

Built to be trusted with driver data.

Driver licences, medicals, hours and home addresses are some of the most personal data an operator holds. This is how Roadworthy looks after them.

How we protect data

Each operator’s data kept apart

Every request is checked against the operator it belongs to before anything is read or written. An operator’s people see only that operator; a consultant sees only the operators they are assigned to. This is tested automatically on every release.

Passwords and PINs hashed

Passwords are stored only as salted scrypt hashes. Driver PINs are hashed the same way with an additional secret kept outside the database. Nobody, including us, can read them.

A tamper-evident audit trail

Sign-ins, failed sign-ins, views of a driver’s record, exports and changes are all recorded. Each entry is chained to the one before it, so a gap or an edit shows.

Records closed, not quietly deleted

A compliance record is closed or withdrawn with a reason, so the history of a defect or an inspection stays intact. The audit log is permanent.

Driver data on request

A driver’s data can be exported, or erased, when they ask. Under UK GDPR the operator is the controller of its fleet records; Roadworthy provides the tools to answer a request properly.

Sign-in protection

Repeated failed sign-ins are slowed down, per account and per connection. Deactivated accounts cannot sign in. “Remember me” can be switched off on a shared yard computer.

Where your data lives

Hosting and access.

Your data is stored on our own server in the EU, and encrypted in transit.

Access needs a signed-in account or a link the operator has issued, such as a workshop’s upload link, which the operator can switch off at any time. Nothing is sold or shared with advertisers, and there is no tracking across other apps or websites.

The full detail is in our privacy notice.

Book a demoBring your security questions to the demo.
Book a demoLog in