optrixTMS
Features How It Works Pricing FAQ
Start Free Trial
Features How It Works Pricing FAQ Start Free Trial

Security

How we protect your data  ·  Optrix TMS

Security is a core part of how Optrix TMS is designed — not an afterthought. This page describes the technical and organisational measures we take to protect your data.

HTTPS / TLS Everywhere
Tenant Data Isolation
Encrypted at Rest & Transit
Cloudflare DDoS Protection

Encryption

All data in transit is encrypted using TLS 1.2 or higher. HTTPS is enforced on all endpoints — there is no HTTP fallback. Data at rest is stored on encrypted volumes managed by our hosting infrastructure.

Tenant Isolation

This is the most important security property of Optrix TMS. Every company (tenant) has its own dedicated database. There are no shared tables between tenants. Even if one tenant's database were somehow compromised, no other tenant's data would be at risk.

Tenant subdomains (e.g. yourcompany.optrixtms.com) are completely isolated at the application and database level.

Authentication

  • Passwords are hashed using bcrypt with a high cost factor — plaintext passwords are never stored.
  • Session tokens are rotated on login and invalidated on logout.
  • CSRF protection is enforced on all state-changing requests.
  • Rate limiting is applied to login endpoints to prevent brute-force attacks.

Infrastructure

  • The platform runs behind Cloudflare, providing DDoS mitigation, WAF protection, and SSL termination.
  • Application servers are hosted on managed shared hosting with cPanel access controls.
  • Database access is restricted to the application server — no external database connections are permitted.
  • File uploads are validated for type and size and stored outside the public web root.

Application Security

  • The application is built on Laravel, which provides built-in protections against SQL injection, XSS and CSRF.
  • All user input is validated and sanitised before processing.
  • Role-based access control (RBAC) is enforced on all routes — users can only access data within their own tenant workspace.
  • Sensitive configuration values (API keys, database credentials) are stored in environment variables, never in source code.

Access Controls

Within each workspace, access is governed by roles (Admin, Operations, Finance, Driver, Carrier). Admins can define which users have access to which modules. All actions are logged in the activity log.

Backups

Tenant databases are backed up regularly by our hosting infrastructure. Backups are retained for a minimum of 7 days.

Responsible Disclosure

If you discover a security vulnerability in Optrix TMS, please report it responsibly. Do not publicly disclose the issue before we have had the opportunity to address it.

Email: [email protected]

We will acknowledge your report within 48 hours and keep you informed as we investigate and resolve the issue. We appreciate the work of security researchers and will credit you in our acknowledgements if you wish.

Questions

For any security-related questions: [email protected]

optrixTMS

Cloud-based transportation management system built for freight forwarders, logistics companies, and carriers of all sizes.

Product

  • Features
  • Pricing
  • How It Works
  • Live Demo
  • Start Free Trial

Company

  • About
  • Contact
  • FAQ

Legal

  • Privacy Policy
  • Terms of Service
  • Security
© 2026 Optrix TMS. All rights reserved.
Privacy Terms Contact