Skip to content

Security

Security and data protection

Konvoi holds data about your vehicles, drivers and money. This page says plainly how it is protected, and what we do not claim.

Where data lives

Konvoi stores your data on infrastructure within the European Union. Every record belongs to one workspace, and every query is scoped to the workspace it is made for, so one company’s data is never mixed with another’s.

Signing in

  • Passkeys (WebAuthn) for a sign-in without a password.
  • Two-factor authentication with an authenticator app, recovery codes or a code by e-mail, per user.
  • Session lock: after a period without activity that each user chooses, from 15 minutes to 8 hours, the session locks and needs to be unlocked again.
  • Short-lived access: access tokens last minutes and are renewed through a rotating, httpOnly cookie; a reused refresh token ends the whole session.
  • Drivers sign in with a magic link sent to their e-mail address.

Who can do what

Each member of a workspace has a role. Admins set the workspace up, users do the everyday work, and viewers can only read: every change by a viewer is refused.

AI with a person in the loop

  • Documents read by AI land in a review inbox; a person confirms them before they change your records.
  • Konvoi Dispatch and the MCP server never change data on their own: every change is a proposal a person approves, and sensitive ones need an admin.
  • Text from outside Konvoi, such as scanned documents and e-mails, is marked as untrusted so AI treats it as data, never as instructions.
  • Every AI client call and every decision on a proposal is logged.

Evidence you can verify

Konvoi Inspect seals each inspection: every file is hashed, signed with a key held in the phone’s Secure Enclave, and timestamped by an independent RFC 3161 timestamp authority. Anyone can verify a report at inspect.konvoi.ai/verify; the check runs in the browser and uploads nothing.

Integrations and API access

  • Partner API tokens carry only the scopes you give them.
  • Webhooks are signed with HMAC-SHA256 and carry a timestamp.
  • AI client connections use OAuth with PKCE, are bound to the Konvoi server, and are revoked when you change your password or log out everywhere.

Your rights

Under the GDPR you can access, correct or delete personal data we hold about you, and object to or restrict its processing. See the privacy policy or write to [email protected].

What we do not claim

Konvoi does not hold an ISO 27001 or SOC 2 certification today. If your procurement needs a data processing agreement or a security questionnaire, ask us at [email protected].

Put your fleet
On Autopilot

One platform for your whole transport operation: live telematics, compliance documents, fuel, drivers and inspections.

  • Early access to the private beta
  • Cancel anytime
  • GDPR compliant
Join the waiting list