Trust & Security

Built with privacy first. Built for enterprise security.

SafetyConnect captures the data your safety team needs, and nothing more. Every product decision starts with the question: will this respect employee privacy and meet enterprise security standards?

CERTIFIED
ISO 27001
ALIGNED
GDPR Ready
COMPLIANT
India DPDP
TESTED
Annual pentest
Privacy by design

Privacy by design, not as an afterthought.

The most common reason organisations hesitate to deploy a driving safety platform is the fear that it will become a surveillance tool. We built SafetyConnect to make that fear concretely unjustified.

01

Business-hours-only by default

The driver app captures trips during working hours only. Employees control whether trips outside work hours are recorded, and the organisation can disable personal-time capture entirely.

02

No camera, no audio

The driver app uses standard phone sensors (GPS, accelerometer, gyroscope) only. We do not capture video, photos, or audio from employee phones.

03

Data minimization

We collect only the data needed for safety insights. Driver scores, trip events, and risk patterns, not personal location histories, contacts, messages, or app usage.

04

Role-based access

Line managers see their team's data. Safety leaders see group-wide patterns. HR sees compliance metrics. Employees see their own scores and trends.

05

Recognition over surveillance

The SafetyConnect Score is designed to reward safe driving and surface top performers, not to punish. Gamified feedback and coaching are the default workflow.

Security & compliance

Enterprise-grade security as standard.

ISO 27001 certified
Independently audited information security management system. Certificate available on request.
Encryption in transit and at rest
TLS 1.2+ for all data in transit. AES-256 for all data at rest in our cloud environments.
Access controls
Role-based access control (RBAC) for all user types. SSO via SAML 2.0 and OAuth 2.0. MFA available for admin roles.
Audit logs
Every user action, login, data access, configuration change, data export, is logged with user ID, timestamp, and source IP.
Vulnerability management
Regular penetration testing by independent firms. Continuous vulnerability scanning. Documented incident response process.
Backup & disaster recovery
Automated daily backups with multi-region redundancy. Documented RTO and RPO targets for enterprise customers.
Data residency

Where your data lives, and who can access it.

SafetyConnect is hosted on AWS, with the flexibility to host your data in the region your security and compliance policies require. Customer data is logically isolated by tenant, and customers retain full ownership of their data.

SafetyConnect does not access customer data except for documented support purposes with customer permission.

INFRASTRUCTURE
AWS
Enterprise-grade cloud, ISO 27001 certified
RESIDENCY
Region of your choice
Hosted in the AWS region your policies require
ISOLATION
Per-tenant
Each customer's data logically isolated
OPTION
On-premise
Available for regulated industries
Governance

Customers control their data.

Data ownership
Customer data is the customer's property. SafetyConnect is the data processor, not the controller.
Data export
Customers can export their full dataset in standard formats (CSV, JSON, PDF) at any time.
Data deletion
On termination, customer data is deleted from production systems within 30 days and from backups within 90 days.
DPA available
Standard DPA available for customers operating under GDPR, India DPDP Act, or other data protection frameworks.
Documentation

Documentation available on request.

We share our full security documentation with your IT and security teams on request, rather than as public downloads. Tell our security team what your review needs and we will provide it.

CERTIFICATE
ISO 27001
On request
WHITEPAPER
Security architecture
On request
TEMPLATE
Data Processing Agreement
On request
ASSESSMENT
CAIQ / SIG-Lite
On request
SUMMARY
Penetration test letter
On request
POLICY
Privacy & AUP
On request
Request documentation from our security team
Direct contact

Have a question we haven't answered?

Enterprise security and procurement teams are welcome to talk to ours directly. We respond to security questionnaires, run vendor assessments, and sit on calls with your CISO's team.

Talk to our security team