Security

Built for operational trust.

FreightSurf is engineered with security at every layer — from how we access your Gmail or Outlook mailbox to how we store your carrier intelligence. This page explains exactly what we do, and what we never do, with your data.

Email Permission Transparency

Exactly what FreightSurf can and cannot do with your Gmail or Outlook mailbox.

FreightSurf connects your mailbox through Nylas, our email connectivity provider. You authorize access through Google's or Microsoft's own OAuth flow — Nylas provides the unified connection layer, and FreightSurf never sees or stores your password. We believe you should understand precisely what permissions are requested and why. No surprises.

What FreightSurf Does

  • Reads your connected Gmail or Outlook mailbox through Nylas to identify inbound carrier emails. For Gmail this uses Google's gmail.readonly scope; for Outlook, the equivalent Microsoft Graph mail-read permission.
  • Temporarily processes inbox messages to classify carrier vs. non-carrier communications.
  • Extracts structured freight intelligence from carrier emails (MC numbers, lanes, rates, equipment).
  • Stores carrier intelligence in your encrypted FreightSurf account database.
  • Sends outbound emails from your connected mailbox through Nylas — for Gmail via Google's gmail.send scope — only when you explicitly compose and authorize an outbound reply within the platform.

What FreightSurf Never Does

  • Never stores the content of non-carrier emails. Non-carrier messages are identified and immediately discarded.
  • Never modifies, archives, moves, labels, or deletes any email in your inbox.
  • Never accesses your calendar, contacts, Drive, OneDrive, or any other provider service beyond your mailbox.
  • Never sends emails autonomously — outbound emails require your explicit authorization every time.
  • Never shares or sells your mailbox data to third parties for their independent use.
  • Never uses your mailbox data for advertising or third-party marketing.
  • Never uses mailbox data to train general-purpose AI models.
  • Never asks for or stores your email password — authorization happens directly with Google or Microsoft.

You can review and revoke FreightSurf's access at any time through your provider's own account settings — for Gmail at myaccount.google.com/permissions, or for Microsoft 365 / Outlook in your Microsoft account's app permissions. When you connect Gmail, FreightSurf's handling of Gmail data complies with the Google API Services User Data Policy, including Limited Use requirements. Nylas provides the underlying email connectivity layer FreightSurf uses to connect to Gmail and Outlook.

Infrastructure

Security at every layer.

Data Encryption

All data transmitted to and from FreightSurf is encrypted in transit using TLS 1.3. All data stored at rest — including carrier intelligence, account data, and extracted freight records — is encrypted using AES-256.

  • TLS 1.3 for all data in transit
  • AES-256 encryption at rest
  • Encrypted database storage
  • Encrypted backup systems

Infrastructure Security

FreightSurf runs on enterprise-grade cloud infrastructure with security controls designed for high-availability operational platforms. We apply security-first architectural practices across all system components.

  • Enterprise cloud hosting with isolated compute environments
  • Continuous infrastructure monitoring and anomaly detection
  • Automatic failover and redundancy systems
  • Regular security reviews of infrastructure configuration
  • Network-level isolation between customer data environments

Authentication & Access Control

FreightSurf enforces strict access control across all system layers. Production system access is restricted to a minimal set of authorized engineers using least-privilege principles.

  • Provider OAuth for Gmail and Outlook via Nylas — no password storage
  • Secure session token management with automatic expiration
  • Least-privilege access model for all internal systems
  • Role-based access controls on Team and Enterprise plans
  • Database access restricted and logged per access event

Monitoring & Audit Logging

FreightSurf maintains comprehensive audit logs of platform activity, including mailbox sync events, carrier verification queries, and user actions within the platform. These logs support transparency and incident response.

  • Platform activity logs retained per plan tier
  • FMCSA verification queries logged and auditable
  • Mailbox sync events logged with timestamps
  • Outbound email actions recorded with user authorization timestamps
  • Security event alerting for anomalous access patterns

AI Data Handling

FreightSurf uses OpenAI's API for natural language processing features. Carrier email content submitted to OpenAI for classification is governed by an enterprise API agreement that prohibits use of your data to train or improve OpenAI's models.

  • OpenAI API-only usage — no shared model training
  • Customer data not used to improve any third-party AI system
  • Encrypted transmission to AI processing endpoints
  • AI outputs are informational — not stored as ground truth
  • Minimal data submission principle — only necessary context sent

Carrier Data Protection

Your carrier intelligence database — the operational core of your FreightSurf account — is isolated, encrypted, and accessible only to your authorized team members.

  • Carrier data stored in isolated per-account namespaces
  • FMCSA data sourced from official government APIs only
  • No cross-account data sharing or aggregated profiling
  • Carrier data exportable on request in standard formats
  • Data deleted within 30 days of account termination

Honest Security Posture

What we don't overclaim.

FreightSurf is built with security-first architecture and enterprise-grade infrastructure practices. We believe in honest security communication.

We do not claim certifications we have not completed. We actively maintain a strong security posture and will update this page as our security program matures.

Security-first architecture

Enterprise-grade cloud infrastructure

AES-256 + TLS 1.3 encryption

Least-privilege access model

SOC 2 Type II certified

Not yet certified. On our roadmap.

ISO 27001 certified

Not currently certified.

HIPAA compliant

Not applicable — no health data processed.

Account security best practices.

The security of your brokerage data is a shared responsibility. Here is what we recommend.

Use a dedicated mailbox

For highest security isolation, connect a dedicated brokerage Gmail or Outlook account to FreightSurf rather than a personal or administrator inbox.

Review connected apps regularly

Periodically review which apps have access to your Google or Microsoft account in your provider's account settings. Revoke any access you no longer need.

Report suspicious activity

If you notice unusual platform activity or suspect unauthorized access to your FreightSurf account, contact support@freightsurf.com immediately.

Have a security question?

Our team is available to answer security questions before you connect your inbox. For vulnerability disclosures, please contact us directly.

For responsible disclosure of security vulnerabilities, please email support@freightsurf.com with subject line “Security Disclosure”.