1. Core controls
- Encryption in transit (TLS) for application traffic.
- Encrypted storage of sensitive integration tokens.
- Workspace isolation and role-based access patterns.
- Webhook verification and service-role hardening on server paths.
- Auditability for automation and approval-sensitive actions.
- Least-privilege Google OAuth scopes for enabled features.
2. Report a vulnerability
Email security concerns to support@haulora.co with “Security” in the subject, or to legal@haulora.co for sensitive disclosures. Please act in good faith and avoid accessing other customers’ data.
Related