๐Ÿ”’ SECURITY & DATA PROTECTION

Your data is protected by design

Drivers Hub handles drivers' personal and compliance information. Here's exactly how we keep it safe โ€” and what we deliberately choose not to keep.

๐Ÿ” Encrypted in transit

Every connection to Drivers Hub is served over HTTPS/TLS and protected at the edge by Cloudflare, with HSTS enforced so browsers never fall back to an insecure connection.

๐Ÿง‚ Passwords never stored in the clear

Passwords are hashed with scrypt (a slow, memory-hard algorithm) and salted per user. We can never see or recover your password โ€” only verify it.

๐Ÿ“ฑ Two-factor authentication

Accounts can enable app-based two-factor authentication (Google Authenticator / TOTP). The owner admin console is protected by 2FA as standard.

๐Ÿ—‘๏ธ Documents deleted after review

Compliance documents you upload โ€” licence, CPC, DBS, right-to-work, proof of address โ€” are used to verify you and then permanently deleted as soon as they're reviewed. We keep the approval result, not the file.

๐Ÿšง Strict access controls

Every account can only ever see and change its own data. Driver records, bank details and private messages are gated to the person they belong to, or the agency that legitimately works with them.

๐Ÿ›ก๏ธ Hardened against abuse

Login and sign-up are rate-limited, sessions are server-side and HttpOnly, and the platform sends a strict set of security headers (CSP, X-Frame-Options, no-sniff) on every response.

What we store โ€” and what we don't

We follow data minimisation: we only keep what's needed to run the service.

Your rights (UK GDPR)

Reliability

Found a security issue?

We welcome responsible disclosure. Email us and we'll respond quickly.

Report a vulnerability