Security
DeliveryOS is built for multi-tenant logistics. This overview is for customers—not a certification claim.
- Tenant separation. Each company workspace is isolated with PostgreSQL Row Level Security and server-side checks on every sensitive RPC.
- Authentication. Phone OTP via Supabase Auth; sessions use industry-standard JWTs.
- Role-based access. Owners, dispatchers, support staff, and riders see only what their role allows.
- Audit trails. Platform and workspace audit events for operational accountability.
- Private storage. Delivery photos and assets use scoped storage policies.
- API keys. Hashed verification server-side; never exposed in the browser bundle.
- Webhooks. Signed payloads for verified integrations.
DeliveryOS does not claim PCI DSS, ISO 27001, SOC 2, or GDPR certification unless separately documented by your organization after legal review.