Security

DeliveryOS is built for multi-tenant logistics. This overview is for customers—not a certification claim.

  • Tenant separation. Each company workspace is isolated with PostgreSQL Row Level Security and server-side checks on every sensitive RPC.
  • Authentication. Phone OTP via Supabase Auth; sessions use industry-standard JWTs.
  • Role-based access. Owners, dispatchers, support staff, and riders see only what their role allows.
  • Audit trails. Platform and workspace audit events for operational accountability.
  • Private storage. Delivery photos and assets use scoped storage policies.
  • API keys. Hashed verification server-side; never exposed in the browser bundle.
  • Webhooks. Signed payloads for verified integrations.

DeliveryOS does not claim PCI DSS, ISO 27001, SOC 2, or GDPR certification unless separately documented by your organization after legal review.