# Each company sees only its own freight.

> How Roadmark keeps each company's freight apart in the database, scopes agents and AI assistants to the person they work for, and records every change.

URL: https://roadmark.ai/security
Language: en

Roadmark keeps every company's loads, customers and rates apart in the database itself. An agent or an AI assistant inherits exactly the access of the person it's working for, never more.

## Each company sees only its own freight.

Roadmark keeps every company's loads, customers and rates apart in the database itself. An agent or an AI assistant inherits exactly the access of the person it's working for, never more.

- **Row-level, not screen-level** Every query is scoped to a company in the database itself, not by a screen deciding what to show.
- **One scope for people, agents and assistants** An agent, or a question asked in Claude, ChatGPT or Gemini, runs as the person who called it and sees only what they see.
- **Every change recorded** Who, what and when, kept for as long as your audit needs.
- **Works without AI** Turn every agent and assistant off, and the platform runs exactly the same.

## One database, and a scope for every company.

The group's companies keep separate data. A person's access is a scope over one company or several, and anything that runs on their behalf, an agent or an AI assistant, inherits that same scope.

## Sign-in stays with your identity provider.

Roadmark doesn't hold a separate password for your team. Sign in with the identity provider you already run, and access follows the role and company you set there.

- **Single sign-on.** Okta and Microsoft 365 today, with more on request.
- **Roles are scoped to a company.** The same person can hold a different role at each company they work in.
- **Access removal.** Confirm session revocation and provisioning behavior for your identity-provider setup during your security review.

## What an agent or an assistant can see.

The same isolation applies whether the question comes from a screen, the API, or a chat with Claude, ChatGPT or Gemini.

- **What can an agent or assistant see?** Only what the person it's working for can see in Roadmark: their companies, their customers and carriers, and nothing wider.
- **Do prompts and results leave our data?** They stay scoped to your company. Ask us for the current list of model providers we use.
- **Does our data train the models?** Roadmark does not use one customer's data to serve another. What a provider does with a conversation depends on your plan with them; your admin can check its terms.
- **Can we turn it off?** Yes, for a person, a team or a whole company, from Roadmark, at any time.

## Every change is recorded: who, what and when.

A change always carries who made it (a person, an agent, an assistant or an integration), what changed, and the time. The record isn't editable after the fact, and it's kept for as long as your audit needs it.

- **Exportable.** Auditors get a file for any date range, not a screen share.
- **Company by company.** An export never includes another company's rows.

## Roadmark keeps running when the AI doesn't.

Every screen, quote and load works without an agent or an assistant, whether a model provider is down or your team has paused them.

- **Works without AI.** No screen or workflow depends on a model responding.
- **Backup requirements.** Discuss retention, restore testing and recovery requirements for your deployment with our team.
- **Service availability.** Contact us for availability information and the incident communication process for your deployment.

## Certifications, data location and who to ask.

- **Certifications** Contact us for current security documentation and to discuss your review requirements. Confirm any required attestation and its scope before contracting.
- **Data location** Tell us your hosting region and deployment requirements. We will confirm the available options and the scope of data residency, including any external processing, before you commit.
- **Security contact** To report a vulnerability, or to ask for a questionnaire or a review:

## Questions IT asks first.

- **Do you support single sign-on?** Yes, through Okta or Microsoft 365 today. Roles and company access follow what you set with your identity provider.
- **How is data isolated between our companies?** Every row belongs to one company, and row-level security in the database enforces it. A person, an agent or an integration can only reach rows in the companies they're scoped to.
- **Can an AI agent or assistant see data outside its scope?** No. It runs as the person who invoked it and inherits exactly their access, never more, whether it's a Roadmark agent or a question asked in Claude, ChatGPT or Gemini.
- **Where is our data hosted, and can we keep a copy?** Confirm the hosting region, external processing, backup locations and export requirements with our team for your deployment before you commit.
- **Can we run Roadmark on our own servers?** Contact our team to discuss your infrastructure requirements and confirm which deployment options can support them.
- **What happens to our data if we leave?** You keep an export of your records, and we delete what remains on the schedule set out in your contract.
- **Who do we contact for a security review or a questionnaire?** Our security team, at the address on this page. Tell us your format and deadline and we'll work to it.

## Related pages

- [Control and safety](https://roadmark.ai/ai-control): Approvals, limits and the record
- [Developers](https://roadmark.ai/developers): REST API, webhooks and MCP
- [Connect your AI assistant](https://roadmark.ai/ai-assistants): Use Roadmark from Claude, ChatGPT or Gemini
- [Integrations](https://roadmark.ai/integrations): ELD, EDI, load boards and accounting
- [Canadian TMS](https://roadmark.ai/canadian-tms): Canadian and cross-border freight workflows, with simple pricing and unlimited users

Companies, people and shipment figures in product examples are fictional. They illustrate workflows and are not customer testimonials or measured results.