Trust center

Security and compliance posture for haulage operations.

GoHaul is built around tenant-scoped access, audit evidence and explicit retention decisions for waste and operational records. This page summarises what is available today and where launch boundaries remain deliberately gated.

GoHaul audit and compliance dashboards on office screens

Tenant isolation

Staff app access is resolved from the server session and tenant membership. Customer portal sessions are a separate auth plane from staff users.

Encrypted transport and storage

TLS, HSTS and provider volume encryption protect the platform baseline. P0 and P1 data paths use stricter handling where the product stores sensitive values.

Audit evidence

Sensitive actions, exports, DSAR operations, manifest lifecycle events and admin activity write audit rows for review and investigation.

Retention by data class

Waste manifests, invoices, audit logs, service requests and operational files are documented separately so legal holds do not get treated like ordinary cleanup.

Compliance evidence

Built for audit trails, not brochure claims.

Waste documents, exports and sensitive actions are treated as evidence surfaces. Access is separated by role and by auth plane, with exports tied back to audit rows.

Waste transfer notes and hazardous consignment notes use signed, tamper-evident records with retention windows.
Manifest PDF downloads, register exports and compliance pack exports are permission-gated and audit-logged.
Drivers and customer portal users are kept out of staff-only document and compliance views unless a specific customer-safe path exists.
Retention sweeps run in report-only mode for gated domains until statutory and operator sign-off allows deletion.

Current public boundaries

No public ISO 27001, SOC 2 or Cyber Essentials certification claim is made here.

No public DPA, cookie inventory or sub-processor download is published until legal review and mailbox ownership are confirmed.

Non-essential analytics and marketing cookies remain blocked until consent tooling and a verified cookie inventory exist.

View security.txt