Skip to main content
Wheelerate

Security

How your organization’s data is protected.

What Wheelerate does to keep each operator’s information separate, private and intact, and where to read the commitments in full.

Measures

  • Each organization kept apart

    Every request carries a signed statement of the organization it acts for, and the database itself refuses any record of another. Automated tests check it before every release.

  • No passwords held here

    People sign in through an identity provider with OpenID Connect, so Wheelerate never receives or stores a password. Where the provider asks for a second factor, that protects Wheelerate too. Sessions end after at most 12 hours.

  • Encrypted connections and backups

    Connections are encrypted between the browser, our network edge, the application and the database. Backups are encrypted before they are stored and can be read only with a recovery key kept offline.

  • Roles, and a record of every change

    Five roles decide what each person can see and do. An append-only record keeps who changed what, and when, for the people allowed to read it.

  • Logs without personal content

    Our logs keep what support and security need: identifiers, times and outcomes. No names, contact details, search terms or anything typed into Wheelerate.

  • Your data stays yours

    Your owners and administrators can correct and de-identify customer and driver records themselves. When you leave, we give you a copy of your data or delete it.

Hosting

Where Wheelerate runs

Google Cloud
The application, its database, backups and logs.
Cloudflare
Delivers the site and the application to browsers, encrypts connections and protects against attacks.
Our sign-in provider
Signs people in to Wheelerate.

The full commitments are in our legal documents:

Found a security problem?

Email hello@wheelerate.com with what you found and how to reproduce it. Please do not read or change anyone else’s data, and do not disrupt the service, while you look.