Who can see what.
And who did what.
Security here means who can see and change what inside your account, and a record of what they did. RushHour enforces both, and keeps your records separate from every other company on it.

Three layers, one platform
Access, isolation, and audit
Access control
Role-based permissions on every page and action
100+ named permissions: set what a dispatcher, accountant, owner-operator or customer contact can open and change. Changes are logged with who, what and when.
- 100+ granular permissions
- Full change audit log
- SSO and 2FAComing soon

Tenant isolation
Your records stay your company's
Every record is scoped to the company that owns it, and the filter runs in the data layer, not in the UI. Drivers and customer contacts see only their own. Industry lane benchmarks are anonymised.
- Per-tenant query filters
- Scoped customer-portal tokens
- Drivers see only their own work

Audit trail
See what changed, who changed it, and when
The activity log splits changes by who made them — your team, the AI assistant, or the system itself — and orders and quotes carry field-level before-and-after history.
- Field-level order and quote history
- User, AI and system activity tabs
- Searchable for 365 days

What security & IT teams check
Tenant isolation
Every record is scoped to the company that owns it.
Role-based access
100+ named permissions, set per role and per action.
Hosted card fields
Card details go straight to Cardknox, never stored by us.
365-day audit log
Who changed what, and when — across orders, quotes and settings.
Walk our security model with your IT team.
We'll cover access, isolation, the audit trail and our DPA — and say straight what we don't have yet.