Trust Center

How portrun protects the record. Every claim below is something the system enforces today — with the evidence that backs it. Where a protection isn't built yet, we say so.

Tenant isolation is a database policy, not a promise.

What one company can see is decided by row-level security in the database itself — not by application code that could forget. Every application table carries it: 189 of 189, counted in the database serving this page. On every change, our build re-proves the structure around that wall — that no view, no function and no grant can read around it — and fails if one can. And when a request falls outside your company, the answer never confirms the record exists.

EvidenceRow-level security on 189 of 189 tables · the view, authority and grant gates in required CI.

The record is append-only and tamper-evident.

Every action is an event in a hash-chained log — each entry carries the fingerprint of the one before it, so a silently altered or deleted event breaks the chain and is caught. Nothing is edited in place.

EvidenceThe event spine · the chain gauge.

Every rate confirmation is verifiable by anyone.

Each executed document carries a SHA-256 fingerprint. A counterparty can check any copy on the public verify page and see whether it is the current, executed version — no account required.

EvidenceThe public verify page.
Open the public verify page

Amendments are loud, never silent.

Changing a signed rate con withdraws both signatures, opens a new version, and preserves the prior one unchanged — in full view of both parties, as a system entry both sides see. There are no quiet edits to an agreement.

EvidenceThe versioned document + withdrawn-signature record.

Administrative access is declared — never silent.

A portrun operator cannot read across companies by default. Platform-wide visibility requires a live, purpose-stated declaration that is itself an audited fact — who, when, why, and when it expires. Without it, every platform view returns nothing.

EvidenceThe declaration log + the ADMIN MODE banner.

Attribution is automatic.

Every event is stamped with the actor who caused it, taken from their verified session — not something the app fills in afterward.

EvidenceServer-side actor stamping.

Refusals speak plainly.

When the system declines an action, the reason shown is the database's own sentence, verbatim — and the refusal is recorded.

EvidenceThe refusal log.

Neutrality is enforced in code, not just stated.

portrun is the record and the toolset, not a party to any freight deal. No fee is taken by portrun on the freight bill. A load received under a carrier's authority is permanently barred from being re-brokered — a control in the code, not a line in a policy.

EvidenceThe provenance firewall.

We hold the last four digits of a licence, never the full number.

The same for a TWIC card. A driver's file on portrun is a name, a phone number, four digits, and the dates things expire. The strongest protection is the data we never took, so we take as little as the work needs.

EvidenceThe driver record: cdl_last4, twic_last4 — no full-number column exists to hold one.

Messages are private; portrun reads only what is escalated.

A conversation belongs to the companies in it. It cannot be read by portrun staff unless the record escalates it — a message held for threats, a dispute, a claim, or a purpose-stated authority grant that expires in 24 hours and is visible to the participants as an event. Nothing is deleted; archiving hides, it never erases. Message bodies are encrypted at rest under a key held by portrun; portrun staff read a message only through the escalation doors.

EvidenceThe message read policy and the authority grant register.

The record signs its day.

Every night the record commits to what the finished day held: one root hash over the day's events, in order, kept in a register that refuses edits and deletions. Anyone holding a copy of yesterday's root can tell whether the record changed underneath it.

Record root for Sep 23, 2026, UTC:b0fc8c1c72a301f9 · 2 events

What we don't claim — yet.

  • portrun holds no third-party security certification (SOC 2, ISO 27001). If we pursue one, it will appear here with its report — asserted only when it is real.
  • Sensitive personal data IS encrypted field by field at rest: people's names and phone numbers exist only as ciphertext under a per-company key, message bodies (and any held originals) under a per-conversation key, and sealed load records under a per-seal key. Email needs its own sentence, because one of them is different: the email you sign in with is the sign-in service's identity, held in the clear by it and by our roster; every other email — an invitee's, an applicant's, a contact's — is ciphertext under a per-company key. A report's comment is business text, not personal data: it passes the same masking wall a message does and rests in the clear. One self-testing gate per class proves it on every push — pii-at-rest, messages-at-rest with verify-privacy, and seals-at-rest — each planting the defect it exists to catch, against a database rebuilt from our full migration history for that run. What we don't claim: uploaded file bytes (documents, evidence) rest under the storage provider's disk encryption, not a key portrun holds — putting them under a per-company key is on the go-live checklist, and we would rather say so than imply it.