Trust Center
How portrun protects the record. Every claim below is something the system enforces today — with the evidence that backs it. Where a protection isn't built yet, we say so.
Tenant isolation is a database policy, not a promise.
What one company can see is decided by row-level security in the database itself — not by application code that could forget. Every application table carries it: 189 of 189, counted in the database serving this page. On every change, our build re-proves the structure around that wall — that no view, no function and no grant can read around it — and fails if one can. And when a request falls outside your company, the answer never confirms the record exists.
The record is append-only and tamper-evident.
Every action is an event in a hash-chained log — each entry carries the fingerprint of the one before it, so a silently altered or deleted event breaks the chain and is caught. Nothing is edited in place.
Every rate confirmation is verifiable by anyone.
Each executed document carries a SHA-256 fingerprint. A counterparty can check any copy on the public verify page and see whether it is the current, executed version — no account required.
Amendments are loud, never silent.
Changing a signed rate con withdraws both signatures, opens a new version, and preserves the prior one unchanged — in full view of both parties, as a system entry both sides see. There are no quiet edits to an agreement.
Administrative access is declared — never silent.
A portrun operator cannot read across companies by default. Platform-wide visibility requires a live, purpose-stated declaration that is itself an audited fact — who, when, why, and when it expires. Without it, every platform view returns nothing.
Attribution is automatic.
Every event is stamped with the actor who caused it, taken from their verified session — not something the app fills in afterward.
Refusals speak plainly.
When the system declines an action, the reason shown is the database's own sentence, verbatim — and the refusal is recorded.
Neutrality is enforced in code, not just stated.
portrun is the record and the toolset, not a party to any freight deal. No fee is taken by portrun on the freight bill. A load received under a carrier's authority is permanently barred from being re-brokered — a control in the code, not a line in a policy.
We hold the last four digits of a licence, never the full number.
The same for a TWIC card. A driver's file on portrun is a name, a phone number, four digits, and the dates things expire. The strongest protection is the data we never took, so we take as little as the work needs.
Messages are private; portrun reads only what is escalated.
A conversation belongs to the companies in it. It cannot be read by portrun staff unless the record escalates it — a message held for threats, a dispute, a claim, or a purpose-stated authority grant that expires in 24 hours and is visible to the participants as an event. Nothing is deleted; archiving hides, it never erases. Message bodies are encrypted at rest under a key held by portrun; portrun staff read a message only through the escalation doors.
The record signs its day.
Every night the record commits to what the finished day held: one root hash over the day's events, in order, kept in a register that refuses edits and deletions. Anyone holding a copy of yesterday's root can tell whether the record changed underneath it.
What we don't claim — yet.
- portrun holds no third-party security certification (SOC 2, ISO 27001). If we pursue one, it will appear here with its report — asserted only when it is real.
- Sensitive personal data IS encrypted field by field at rest: people's names and phone numbers exist only as ciphertext under a per-company key, message bodies (and any held originals) under a per-conversation key, and sealed load records under a per-seal key. Email needs its own sentence, because one of them is different: the email you sign in with is the sign-in service's identity, held in the clear by it and by our roster; every other email — an invitee's, an applicant's, a contact's — is ciphertext under a per-company key. A report's comment is business text, not personal data: it passes the same masking wall a message does and rests in the clear. One self-testing gate per class proves it on every push — pii-at-rest, messages-at-rest with verify-privacy, and seals-at-rest — each planting the defect it exists to catch, against a database rebuilt from our full migration history for that run. What we don't claim: uploaded file bytes (documents, evidence) rest under the storage provider's disk encryption, not a key portrun holds — putting them under a per-company key is on the go-live checklist, and we would rather say so than imply it.