FleetTask

Security at FleetTask

Security summary · Last updated 25 September 2026

FleetTask is designed to keep each operator's information separated and to make important activity accountable.

Identity and access

Every user enrolls a time-based authenticator at first sign-in. Authenticator secrets are encrypted. Passwords are salted and derived, temporary passwords must be changed, permissions are enforced on the server, recovery actions are audited and sessions expire after one hour of inactivity.

Application and files

Production traffic uses HTTPS and secure HttpOnly cookies. Uploads are validated and must pass antivirus scanning. Security and operational changes are retained in audit history. Private documents are available only through authorised application requests.

Recovery

Production uses daily hosting-provider backups and a separate daily off-server application backup. FleetTask can restore one operator independently. Backup failures alert the platform owner, and restore procedures are tested on a schedule.

Reporting a concern

Send suspected vulnerabilities or incidents to security@fleet-task.com. Include the affected URL, time and safe reproduction detail. Do not access other users' data or disrupt the live service.

← Back to FleetTask