Fleet Compliance Risk Auditor

We Find the Problems
Before an Auditor Does.

Your ELD records what happened. Fleet Audit determines what an auditor, insurer, or plaintiff's lawyer will question.

HOS violations, falsified logs, missing supporting documents, suspicious edits, unidentified miles — all surfaced before DOT or a courtroom does.

Samsara · Motive · Geotab · ISAAC · BigRoad · Garmin eLog · any CSV or Excel export

Scroll to explore

"Your logs are not just records. They are your legal defense — or your liability. Are your logs defensible?"

Pre-audit risk detection for HOS, ELD, supporting-document, and log-integrity issues — before DOT, FMCSA, Transport Canada, insurance, or a plaintiff's lawyer finds them.

50+

Violation Types Detected

13+

Jurisdictions Covered

100%

Deterministic Rule Checks

v1.3

CCMTA Standard Compliant

The Full Audit Scope

Everything we examine
on every single audit

This is what a DOT auditor looks for. We look first.

HOS Violations

  • 11h / 13h driving limit (US & Canada)
  • 14h / 16h duty window
  • 30-min break rule (FMCSA)
  • 60h / 70h / 80h cycle limits
  • Sleeper berth split rules
  • Short-haul exception misuse
  • Alberta deferral rule
  • Cross-border HOS transitions

Log Integrity

  • Excessive edits & retroactive changes
  • Driving status changed after the fact
  • Unsigned / uncertified logs
  • Unidentified driving time
  • Sequence number gaps
  • Rapid fake-break transitions
  • Copied identical remarks
  • ELD malfunction indicators

Falsification Flags

  • Ghost movement (off-duty odometer jump)
  • Speed manipulation (>105 km/h implied)
  • Fuel receipt while off-duty
  • Personal conveyance misuse
  • Yard move on public roads
  • Location conflict: GPS vs. document
  • CCMTA §4.4.5 checksum tamper
  • Missing certifying driver signature

Supporting Docs

  • Fuel receipts vs. duty status
  • BOL pickup/delivery timing
  • Scale & toll ticket cross-reference
  • DVIR pre-trip inspection
  • Location: doc vs. ELD GPS
  • Oilfield waiting ticket validation
  • Document timestamp conflicts
  • Missing supporting documentation

Platform Capabilities

Built for the worst case.
Ready for every inspection.

The rule engine is deterministic. The AI explains, prioritizes, and reports. Never the other way around.

Deterministic HOS Rules Engine

Every HOS rule is hard-coded — not guessed by AI. 13h driving, 14h window, 16h elapsed, cycle limits, sleeper berth splits, cross-border transitions. The engine calculates. AI explains.

Log Integrity & Edit Forensics

Excessive edits, retroactive status changes, copied remarks, rapid fake-break transitions, sequence number gaps, driver certification missing — all flagged with rule citations.

Supporting Document Mismatch

Fuel receipts while off-duty, BOL pickup while driving, location conflicts between GPS and receipts, missing pre-trip DVIR — we cross-reference every document against every log.

Falsification Detection

Ghost movement, odometer jumps, speed manipulation (>105 km/h implied), unidentified driving, personal conveyance misuse, yard move fraud — court-grade evidence documentation.

Auto Jurisdiction Switching

GPS-triggered rule switching. Cross into the US? FMCSA kicks in. North of 60°? Extended limits applied. Alberta, BC, Quebec, Ontario, SK, MB provincial rules — all automatic.

CCMTA §4.4.5 Data Integrity

Full cryptographic checksum verification per CCMTA Technical Standard v1.3. Every line and file-level checksum verified. Tampered files flagged instantly.

Court-Ready AI Reports

One click: executive summary, violation narrative, falsification analysis, jurisdiction analysis, formal certification. Built for DOT hearings, insurance reviews, and courtrooms.

Fleet & Driver Risk Scoring

Compliance scores, traffic-light driver status, near-violations, unidentified miles, edit patterns, recurring issues — all surfaced so safety managers know exactly where to focus.

All Canadian Jurisdictions + US

Federal NSC Standard 9, all 13 provinces & territories, US FMCSA 49 CFR Part 395, cross-border transition rules, oilfield exemptions, short-haul exceptions.

The Process

From ELD export to
audit-ready report in minutes

01

Upload ELD Export

Drag and drop any ELD log — CSV, Excel, XML — from Samsara, Motive, Geotab, ISAAC, or any other platform. Or paste a Google Sheet link.

02

Engine Audits Everything

The deterministic rules engine checks every HOS rule, every jurisdiction, every edit, every document cross-reference. AI never touches the math — only the explanations.

03

Violations & Risks Surfaced

Every violation is flagged with a rule citation, severity level, and evidence. Falsification flags include specific odometer values, speeds, timestamps, and document conflicts.

04

Report Generated

One click: a full legal-grade compliance report with executive summary, findings, jurisdiction analysis, falsification evidence, and certifying officer signature for court use.

Who Uses Fleet Audit

10–100 Truck Fleets

Big enough for compliance pain. Small enough to lack a full safety department.

Safety Consultants

Audit more clients, faster. White-label reports under your brand.

Post-Violation Carriers

Recent DOT violation or insurance pressure? You need to find the rest first.

Cross-Border Carriers

Canada/US complexity, dual-ruleset transitions, and bilingual reports.

Security & Compliance

Your audit data is protected
like a court exhibit.

Fleet Audit is built on a SOC 2 Type II and ISO 27001 certified platform, secured by Google OAuth, and hardened with our own tenant-isolation and forensic-integrity layers.

SOC 2 Type II

Independently audited security controls

ISO 27001

Certified information security management

GDPR

EU data protection + DPA on request

PCI DSS

Certified payment processing

Platform Security

Inherited from our certified infrastructure — every Fleet Audit account gets these by default.

AES-256 Encryption at Rest

Every record, file, and audit report encrypted with AES-256 — the same standard used by banks and governments. Backups are encrypted too.

TLS 1.2+ Encryption in Transit

All data moving between your browser, our servers, and integrations is encrypted with modern TLS. No plaintext, ever.

Cloud KMS Secret Management

API keys, Stripe secrets, and OAuth credentials live in a managed key vault — never in code, never in the database.

24/7/365 Security Operations Center

A dedicated SOC team monitors the platform around the clock with SIEM technology. Threats are detected and contained in real time.

Continuous Security Scans

Every app is scanned for vulnerable dependencies (SCA), insecure code patterns (SAST), exposed secrets, and weak access rules — with AI-assisted fixes.

Penetration Testing & Bug Bounty

Internal teams and third-party firms test defenses using OWASP methodologies. An independent bug bounty program rewards responsible disclosure.

Disaster Recovery & Backups

Defined Recovery Time and Recovery Point Objectives, frequent automated backups, and documented recovery procedures.

Cloudflare CDN Protection

All traffic is protected by Cloudflare's edge network — DDoS mitigation, WAF, and bot management included.

Authentication & Access Control

Google OAuth 2.0 + role-based permissions + enterprise SSO.

Google OAuth 2.0 + OpenID Connect

Sign-in is handled by Google's OAuth 2.0 / OIDC infrastructure — we never see or store your Google password. Scopes limited to openid and email.

Anti-Bot & Email Verification

Google's anti-abuse controls plus mandatory email verification on every account. Optional 2FA via authenticator app or SMS.

Role-Based Access Control

Admin and user roles with scoped permissions. Only admins can manage carriers, invite users, or access cross-tenant data.

SSO Enforcement (Enterprise)

Organizations can enforce SSO across the workspace via OIDC — Entra ID, Okta, Google, and more. SCIM provisioning for automated lifecycle management.

IP Allowlist (Enterprise)

Restrict access to specific IPs, CIDR ranges, and IPv6 networks. Requests from anywhere else are rejected with a 403.

Workspace API Keys

Scoped API keys for integrations and monitoring — each key carries only the permissions you grant it.

Fleet Audit Application Security

The extra layer we've built on top — tenant isolation, forensic integrity, and document protection.

Row-Level Security (Tenant Isolation)

Every entity enforces RLS — carriers can only see, edit, or delete their own drivers, audits, violations, and documents. Enforced at the database layer, not just the UI.

CCMTA §4.4.5 Cryptographic Integrity

Full line-level and file-level checksum verification on every eRODS upload. Tampered or altered ELD files are flagged instantly with forensic evidence.

Audit Trail & Forensic Evidence

Every violation carries preserved ELD evidence, document cross-references, and rule citations — court-admissible and timestamped.

PCI-Compliant Stripe Payments

Subscription billing runs through Stripe's PCI DSS-certified infrastructure. We never store card numbers — Stripe handles tokenization and fraud detection.

Private File Storage

Sensitive audit reports and supporting documents are stored privately with signed, time-limited download URLs — no public access.

Data Residency Controls

Choose where your app data is stored — US, EU, or UK. Available for enterprise workspaces.

Audit Logs (Enterprise)

A complete record of who did what — sign-ins, publishing, governance events — streamable to your own monitoring tools via API.

GDPR Deletion & Data Opt-Out

Right-to-erasure flows and the ability to opt your workspace's data out of AI model training.

End-to-end encryption, at rest and in transit

AES-256 at rest. TLS 1.2+ in transit. Cloud KMS-managed keys. Encrypted backups. Your ELD data, audit reports, and supporting documents are protected at every layer — from upload to courtroom.

Security Roadmap — In Progress

These measures are actively being implemented. Listed here for transparency with security-conscious carriers evaluating the platform.

Custom Google OAuth branding (own domain on consent screen)
Mandatory 2FA enforcement for all carrier admin accounts
Signed audit report PDFs with tamper-evident hashing
Data retention policy engine with auto-purge schedules
Workspace security center for carrier admins
SCIM-based user provisioning from carrier IdPs
Audit log streaming to external SIEM (Splunk, Datadog)
Annual third-party penetration test of Fleet Audit app layer
Data Processing Agreement (DPA) template for carriers
Subprocessor disclosure page for carrier security reviews

Pricing

Simple, transparent pricing

🚀 Free during beta — no payment, no trial, no limits. Paid plans return after beta.

Small Fleet

Up to 10 drivers

FreeBeta
  • Full HOS rules engine
  • Log integrity detection
  • Falsification flagging
  • Fleet risk dashboard
  • AI compliance reports
  • AI fleet assistant
Most Popular

Large Fleet

Up to 50 drivers

FreeBeta
  • Everything in Small Fleet
  • Supporting doc cross-reference
  • Batch fleet audit reports
  • Legal defense reports
  • Driver risk scoring
  • Priority support

Enterprise

Unlimited drivers

FreeBeta
  • Everything in Large Fleet
  • Court submission reports
  • White-label option
  • Safety consultant access
  • Dedicated account manager
  • Custom ELD integrations

Court submission and legal defense reports available as add-ons. Safety consultant plans available. Contact us for enterprise pricing.

Find the problems
before they find you.

Carriers are getting fined, losing court cases, and paying lawyers because they have no proper audit trail. Fleet Audit reviews your logs like an auditor would — and tells you exactly what needs to be fixed.

No credit card required. Set up in minutes.