ISO 27001
Information Security Management. Our controls for confidentiality, integrity and availability of fleet data are formally documented and audited.
Fleet data is sensitive: locations, drivers, routes, costs. IntelliFleet 360 is built and audited to protect it — with certified security, regional data residency, transparent sub-processors and 99.95% uptime you can verify.
Certified, audited and compliant
Independently assessed frameworks that cover information security, road safety, risk and data protection — plus the local certifications East African fleets are actually audited against.
Information Security Management. Our controls for confidentiality, integrity and availability of fleet data are formally documented and audited.
Road Traffic Safety Management. The standard behind our safety scoring and incident workflows — proof that our tools are built to cut collisions.
Risk Management. A structured approach to identifying, assessing and treating operational risk — for our platform and for your fleet.
Data subject rights, lawful basis, purpose limitation and breach notification — aligned with GDPR and Kenya's Data Protection Act, 2019.
Reports, speed-governor logs and renewal tracking in exactly the format Kenya's National Transport & Safety Authority expects at audit.
Our hardware meets Kenya Bureau of Standards requirements — the tracking and camera devices we install are type-approved for local use.
Registered with Kenya's Office of the Data Protection Commissioner as a Data Controller and a Data Processor (ID 734-773B-7D9C). See all compliance documents.
Every layer — the device on the vehicle, the network, the platform and your team's access — is designed to keep fleet data private and available.
All traffic — device to cloud, browser to API — is encrypted with TLS 1.2+. No fleet telemetry ever crosses the network in the clear.
Stored data is encrypted with AES-256. Keys are managed in a hardened key-management service with strict rotation and separation of duties.
Role-based access, SSO and enforced MFA. Least-privilege by default, with every administrative action written to an immutable audit log.
Fleet data is hosted in-region and stays within the markets we serve. We tell you exactly where your data lives and never sell it.
Regular third-party penetration tests and control audits. Summary reports are available under NDA as part of our security pack.
24/7 monitoring, automated alerting and a documented incident-response plan with defined recovery objectives and backups.
Clear policies for the questions security, legal and procurement teams always ask.
We maintain a current list of the sub-processors that help us deliver the service, what each is used for and where they operate. We give notice before adding new ones.
View sub-processor listFound a vulnerability? We want to hear from you. Report it to our security team and we'll acknowledge quickly, investigate and keep you updated. We don't pursue good-faith researchers.
Report a vulnerabilityA GDPR-ready DPA is available to every customer, covering roles, security measures, sub-processing, international transfers and breach notification. Signed as part of onboarding.
Request a DPARequest our security pack — certifications, architecture overview, penetration-test summaries and the DPA — or talk to our team about your specific requirements.