Skip to content
roadmark

TMS security and data isolation

Each company sees only its own freight.

Roadmark keeps every company's loads, customers and rates apart in the database itself. An agent or an AI assistant inherits exactly the access of the person it's working for, never more.

Row-level, not screen-level
Every query is scoped to a company in the database itself, not by a screen deciding what to show.
One scope for people, agents and assistants
An agent, or a question asked in Claude, ChatGPT or Gemini, runs as the person who called it and sees only what they see.
Every change recorded
Who, what and when, kept for as long as your audit needs.
Works without AI
Turn every agent and assistant off, and the platform runs exactly the same.

How isolation works

One database, and a scope for every company.

The group's companies keep separate data. A person's access is a scope over one company or several, and anything that runs on their behalf, an agent or an AI assistant, inherits that same scope.

How access and isolation work across the group's companies
Access and isolationAshgrove Transportation Group
  • Ashgrove Freight

    • Loads and dispatch
    • Drivers and units
    • Customer rates

    Group controller

  • Ashgrove Logistics

    • Quotes and RFQs
    • Carrier network
    • Customer rates

    Group controller

  • Keel Transport

    • Loads, on McLeod
    • Its own carriers
    • Its own invoices

    Group controllerKeel dispatcher

Each chip is one person's access. The group controller's scope spans all three companies; the Keel dispatcher's scope stops at Keel.

Every agent, and a question asked in Claude, ChatGPT or Gemini, runs as the person who called it. It carries exactly the same chips, and never more.

The database enforces it. Row-level security refuses a query that reaches outside a person's companies, whether it comes from a screen, the API, an integration or an assistant.

Identity and access

Sign-in stays with your identity provider.

Roadmark doesn't hold a separate password for your team. Sign in with the identity provider you already run, and access follows the role and company you set there.

  • Single sign-on. Okta and Microsoft 365 today, with more on request.
  • Roles are scoped to a company. The same person can hold a different role at each company they work in.
  • Access removal. Confirm session revocation and provisioning behavior for your identity-provider setup during your security review.
Access by role
Access, by role
Access by role
RoleCompaniesCan approve
Group controllerAll companiesEverything at its level
Company adminOne companyEverything in that company
DispatcherOne companyBoard and tracking only
Billing clerkOne companyInvoices and pay only

What an agent or an assistant can see.

The same isolation applies whether the question comes from a screen, the API, or a chat with Claude, ChatGPT or Gemini.
  • What can an agent or assistant see?

    Only what the person it's working for can see in Roadmark: their companies, their customers and carriers, and nothing wider.

  • Do prompts and results leave our data?

    They stay scoped to your company. Ask us for the current list of model providers we use.

  • Does our data train the models?

    Roadmark does not use one customer's data to serve another. What a provider does with a conversation depends on your plan with them; your admin can check its terms.

  • Can we turn it off?

    Yes, for a person, a team or a whole company, from Roadmark, at any time.

Records

Every change is recorded: who, what and when.

A change always carries who made it (a person, an agent, an assistant or an integration), what changed, and the time. The record isn't editable after the fact, and it's kept for as long as your audit needs it.

  • Exportable. Auditors get a file for any date range, not a screen share.
  • Company by company. An export never includes another company's rows.
An audit export request
Audit export
FormatCSV or JSON
RangeAny date range you choose
IncludesWho, what changed, before and after, and where it came from

Availability

Roadmark keeps running when the AI doesn't.

Every screen, quote and load works without an agent or an assistant, whether a model provider is down or your team has paused them.

  • Works without AI. No screen or workflow depends on a model responding.
  • Backup requirements. Discuss retention, restore testing and recovery requirements for your deployment with our team.
  • Service availability. Contact us for availability information and the incident communication process for your deployment.

Compliance

Certifications, data location and who to ask.

  • CertificationsContact us for current security documentation and to discuss your review requirements. Confirm any required attestation and its scope before contracting.
  • Data locationTell us your hosting region and deployment requirements. We will confirm the available options and the scope of data residency, including any external processing, before you commit.
  • Security contactTo report a vulnerability, or to ask for a questionnaire or a review: hello@roadmark.ai

Questions

Questions IT asks first.

Do you support single sign-on?

Yes, through Okta or Microsoft 365 today. Roles and company access follow what you set with your identity provider.

How is data isolated between our companies?

Every row belongs to one company, and row-level security in the database enforces it. A person, an agent or an integration can only reach rows in the companies they're scoped to.

Can an AI agent or assistant see data outside its scope?

No. It runs as the person who invoked it and inherits exactly their access, never more, whether it's a Roadmark agent or a question asked in Claude, ChatGPT or Gemini.

Where is our data hosted, and can we keep a copy?

Confirm the hosting region, external processing, backup locations and export requirements with our team for your deployment before you commit.

Can we run Roadmark on our own servers?

Contact our team to discuss your infrastructure requirements and confirm which deployment options can support them.

What happens to our data if we leave?

You keep an export of your records, and we delete what remains on the schedule set out in your contract.

Who do we contact for a security review or a questionnaire?

Our security team, at the address on this page. Tell us your format and deadline and we'll work to it. hello@roadmark.ai

Talk to our security team.

Send us your questionnaire, or book a call with the person who can answer it directly.

  • A straight answer, not a sales call
  • Your IT and security team are welcome
  • An NDA first, if you need one

Straight to our security team, not sales.

We use this to reply to your request. Privacy policy.