Your ELD records what happened. Fleet Audit determines what an auditor, insurer, or plaintiff's lawyer will question.
HOS violations, falsified logs, missing supporting documents, suspicious edits, unidentified miles — all surfaced before DOT or a courtroom does.
Samsara · Motive · Geotab · ISAAC · BigRoad · Garmin eLog · any CSV or Excel export
50+
Violation Types Detected
13+
Jurisdictions Covered
100%
Deterministic Rule Checks
v1.3
CCMTA Standard Compliant
The Full Audit Scope
This is what a DOT auditor looks for. We look first.
Platform Capabilities
The rule engine is deterministic. The AI explains, prioritizes, and reports. Never the other way around.
Every HOS rule is hard-coded — not guessed by AI. 13h driving, 14h window, 16h elapsed, cycle limits, sleeper berth splits, cross-border transitions. The engine calculates. AI explains.
Excessive edits, retroactive status changes, copied remarks, rapid fake-break transitions, sequence number gaps, driver certification missing — all flagged with rule citations.
Fuel receipts while off-duty, BOL pickup while driving, location conflicts between GPS and receipts, missing pre-trip DVIR — we cross-reference every document against every log.
Ghost movement, odometer jumps, speed manipulation (>105 km/h implied), unidentified driving, personal conveyance misuse, yard move fraud — court-grade evidence documentation.
GPS-triggered rule switching. Cross into the US? FMCSA kicks in. North of 60°? Extended limits applied. Alberta, BC, Quebec, Ontario, SK, MB provincial rules — all automatic.
Full cryptographic checksum verification per CCMTA Technical Standard v1.3. Every line and file-level checksum verified. Tampered files flagged instantly.
One click: executive summary, violation narrative, falsification analysis, jurisdiction analysis, formal certification. Built for DOT hearings, insurance reviews, and courtrooms.
Compliance scores, traffic-light driver status, near-violations, unidentified miles, edit patterns, recurring issues — all surfaced so safety managers know exactly where to focus.
Federal NSC Standard 9, all 13 provinces & territories, US FMCSA 49 CFR Part 395, cross-border transition rules, oilfield exemptions, short-haul exceptions.
The Process
Drag and drop any ELD log — CSV, Excel, XML — from Samsara, Motive, Geotab, ISAAC, or any other platform. Or paste a Google Sheet link.
The deterministic rules engine checks every HOS rule, every jurisdiction, every edit, every document cross-reference. AI never touches the math — only the explanations.
Every violation is flagged with a rule citation, severity level, and evidence. Falsification flags include specific odometer values, speeds, timestamps, and document conflicts.
One click: a full legal-grade compliance report with executive summary, findings, jurisdiction analysis, falsification evidence, and certifying officer signature for court use.
Who Uses Fleet Audit
10–100 Truck Fleets
Big enough for compliance pain. Small enough to lack a full safety department.
Safety Consultants
Audit more clients, faster. White-label reports under your brand.
Post-Violation Carriers
Recent DOT violation or insurance pressure? You need to find the rest first.
Cross-Border Carriers
Canada/US complexity, dual-ruleset transitions, and bilingual reports.
Fleet Audit is built on a SOC 2 Type II and ISO 27001 certified platform, secured by Google OAuth, and hardened with our own tenant-isolation and forensic-integrity layers.
SOC 2 Type II
Independently audited security controls
ISO 27001
Certified information security management
GDPR
EU data protection + DPA on request
PCI DSS
Certified payment processing
Inherited from our certified infrastructure — every Fleet Audit account gets these by default.
AES-256 Encryption at Rest
Every record, file, and audit report encrypted with AES-256 — the same standard used by banks and governments. Backups are encrypted too.
TLS 1.2+ Encryption in Transit
All data moving between your browser, our servers, and integrations is encrypted with modern TLS. No plaintext, ever.
Cloud KMS Secret Management
API keys, Stripe secrets, and OAuth credentials live in a managed key vault — never in code, never in the database.
24/7/365 Security Operations Center
A dedicated SOC team monitors the platform around the clock with SIEM technology. Threats are detected and contained in real time.
Continuous Security Scans
Every app is scanned for vulnerable dependencies (SCA), insecure code patterns (SAST), exposed secrets, and weak access rules — with AI-assisted fixes.
Penetration Testing & Bug Bounty
Internal teams and third-party firms test defenses using OWASP methodologies. An independent bug bounty program rewards responsible disclosure.
Disaster Recovery & Backups
Defined Recovery Time and Recovery Point Objectives, frequent automated backups, and documented recovery procedures.
Cloudflare CDN Protection
All traffic is protected by Cloudflare's edge network — DDoS mitigation, WAF, and bot management included.
Google OAuth 2.0 + role-based permissions + enterprise SSO.
Google OAuth 2.0 + OpenID Connect
Sign-in is handled by Google's OAuth 2.0 / OIDC infrastructure — we never see or store your Google password. Scopes limited to openid and email.
Anti-Bot & Email Verification
Google's anti-abuse controls plus mandatory email verification on every account. Optional 2FA via authenticator app or SMS.
Role-Based Access Control
Admin and user roles with scoped permissions. Only admins can manage carriers, invite users, or access cross-tenant data.
SSO Enforcement (Enterprise)
Organizations can enforce SSO across the workspace via OIDC — Entra ID, Okta, Google, and more. SCIM provisioning for automated lifecycle management.
IP Allowlist (Enterprise)
Restrict access to specific IPs, CIDR ranges, and IPv6 networks. Requests from anywhere else are rejected with a 403.
Workspace API Keys
Scoped API keys for integrations and monitoring — each key carries only the permissions you grant it.
The extra layer we've built on top — tenant isolation, forensic integrity, and document protection.
Row-Level Security (Tenant Isolation)
Every entity enforces RLS — carriers can only see, edit, or delete their own drivers, audits, violations, and documents. Enforced at the database layer, not just the UI.
CCMTA §4.4.5 Cryptographic Integrity
Full line-level and file-level checksum verification on every eRODS upload. Tampered or altered ELD files are flagged instantly with forensic evidence.
Audit Trail & Forensic Evidence
Every violation carries preserved ELD evidence, document cross-references, and rule citations — court-admissible and timestamped.
PCI-Compliant Stripe Payments
Subscription billing runs through Stripe's PCI DSS-certified infrastructure. We never store card numbers — Stripe handles tokenization and fraud detection.
Private File Storage
Sensitive audit reports and supporting documents are stored privately with signed, time-limited download URLs — no public access.
Data Residency Controls
Choose where your app data is stored — US, EU, or UK. Available for enterprise workspaces.
Audit Logs (Enterprise)
A complete record of who did what — sign-ins, publishing, governance events — streamable to your own monitoring tools via API.
GDPR Deletion & Data Opt-Out
Right-to-erasure flows and the ability to opt your workspace's data out of AI model training.
AES-256 at rest. TLS 1.2+ in transit. Cloud KMS-managed keys. Encrypted backups. Your ELD data, audit reports, and supporting documents are protected at every layer — from upload to courtroom.
These measures are actively being implemented. Listed here for transparency with security-conscious carriers evaluating the platform.
Pricing
🚀 Free during beta — no payment, no trial, no limits. Paid plans return after beta.
Up to 10 drivers
Up to 50 drivers
Unlimited drivers
Court submission and legal defense reports available as add-ons. Safety consultant plans available. Contact us for enterprise pricing.
Carriers are getting fined, losing court cases, and paying lawyers because they have no proper audit trail. Fleet Audit reviews your logs like an auditor would — and tells you exactly what needs to be fixed.
No credit card required. Set up in minutes.