Security

Who can see what.
And who did what.

Security here means who can see and change what inside your account, and a record of what they did. RushHour enforces both, and keeps your records separate from every other company on it.

Access and audit controls

Three layers, one platform

Access, isolation, and audit

Access control

Role-based permissions on every page and action

100+ named permissions: set what a dispatcher, accountant, owner-operator or customer contact can open and change. Changes are logged with who, what and when.

  • 100+ granular permissions
  • Full change audit log
  • SSO and 2FAComing soon
Role-based permissions on every page and action

Tenant isolation

Your records stay your company's

Every record is scoped to the company that owns it, and the filter runs in the data layer, not in the UI. Drivers and customer contacts see only their own. Industry lane benchmarks are anonymised.

  • Per-tenant query filters
  • Scoped customer-portal tokens
  • Drivers see only their own work
Your records stay your company's

Audit trail

See what changed, who changed it, and when

The activity log splits changes by who made them — your team, the AI assistant, or the system itself — and orders and quotes carry field-level before-and-after history.

  • Field-level order and quote history
  • User, AI and system activity tabs
  • Searchable for 365 days
See what changed, who changed it, and when

What security & IT teams check

Tenant isolation

Every record is scoped to the company that owns it.

Role-based access

100+ named permissions, set per role and per action.

Hosted card fields

Card details go straight to Cardknox, never stored by us.

365-day audit log

Who changed what, and when — across orders, quotes and settings.

Walk our security model with your IT team.

We'll cover access, isolation, the audit trail and our DPA — and say straight what we don't have yet.