TopOff logoTOPOFFFLEET FUEL INTELLIGENCE
Trust

Security at TopOff

The product's whole premise is a number your finance team can trust, that only works if the data handling underneath is just as disciplined. Here's how we treat yours.

Data protection

  • All traffic encrypted in transit (TLS); data encrypted at rest on AWS infrastructure
  • Strict per-fleet workspace isolation, one fleet's data is never visible to, or pooled with, another's
  • Card transaction data is used solely to verify fill-ups and compute savings, never resold, never used for advertising
  • No personal payment credentials, ever: TopOff has no personal card numbers to lose

Access & operations

  • Least-privilege production access, limited to the founding team, behind SSO with short-lived credentials
  • Every posted savings figure is auditable end-to-end via its card transaction ID
  • Error monitoring and alerting on all production services
  • Serverless architecture (AWS Lambda + DynamoDB), no long-lived servers to patch or forget

Driver privacy by design

  • Location is used only while the app is open, no background tracking, no location history profiles
  • No personal accounts or personal cards; drivers exist only inside the fleet's workspace
  • No advertising or cross-app tracking SDKs in the app
  • Full details in our privacy policy, written to be read

Compliance direction

  • Controls are built along SOC 2 lines from day one; a formal audit is on our roadmap as we scale
  • A security summary and completed questionnaires are available for IT review during procurement
  • We'll sign reasonable data-protection terms with enterprise customers
Found a vulnerability? Tell us at support@topoffintel.com, reports are read by the founders and acknowledged fast. Good-faith research is welcome.

Need it in writing for IT?

Security summary + questionnaire, ready for your review process.

Request the security packet