Security
The boundary sits under the application
A brokerage's loads, customers, rates and margins are the most commercially sensitive things it owns, and a TMS holds all of them at once. The question worth asking a vendor is not whether they separate one customer from another — everybody says yes — but where that separation is enforced.
Row-level isolation, per brokerage
Separation that lives in application code holds until somebody forgets a filter on one query, and then it does not hold at all — quietly, in a report nobody reads carefully.
In Freightiva every row belongs to a brokerage, and the database itself refuses to return rows belonging to a different one. The boundary is underneath the application rather than inside it, so a query that forgets to filter returns nothing instead of returning somebody else's loads. It is the difference between a rule and a wall.
The same mechanism carries down to agencies and offices inside a brokerage, so an agency program can put many independent books in one system without the books being able to see each other.
Two-factor sign-in
A password on its own is a credential that can be phished, reused or bought. Freightiva supports a second factor at sign-in, and second-factor secrets are protected the same way bank details are: encrypted with a key held outside the database, so a stolen copy of the database does not hand over the means to sign in.
Audit trails
Who changed the rate. Who approved the payout. Who released the credit limit, and when. Who accepted the rate confirmation, from which contact on the carrier's record.
These are recorded as they happen and kept with the load or the customer they belong to, which matters twice: once when a customer disputes something months later, and once when you need to know whether an incident was a mistake or a pattern. Sign-in records — time, network address, device description — are kept too, so a broker can investigate a suspicious sign-in without asking us to go looking.
Permissions per office, per agency, per person
An agency sees its own book. An office sees its own office. What somebody can do is set by their role and where they sit, not by whether they know the URL.
Around money the rules are stricter and deliberate: the people who can approve a payout are the people you named, and nobody approves their own pay. Credit decisions sit with the broker rather than the agency requesting the limit, because the broker is the one carrying the receivable and the insurance.
Your data stays yours
A broker's data belongs to the broker. We hold and process it on their instructions so the software can work, and we do not sell it, rent it, or use it to build advertising profiles. If a broker leaves, they take their data with them and we delete our copy, subject to the records a broker is required to keep.
What we hold, who else ever sees it, and how long it is kept is set out in full in the privacy policy — including what the driver app collects, when it stops, and why transaction records are kept for three years.
Questions from your IT or insurance people are welcome and get a real answer: hello@freightiva.app.