Security at HaulStory
HaulStory processes transport email and documents to build source-backed timelines. This page explains the practical controls used to protect that data.
Last reviewed: 21 September 2026
Access is authenticated and scoped to your organization
User access is limited to the organizations a person is authorized to use. Passwords and API credentials are not stored in plaintext, and document download links expire after a limited time.
Organization-scoped access
User access is authenticated and limited to the organizations a person is authorized to use. Super-admin operations require a separate authorization check.
Hashed credentials
User passwords and API credentials are stored as one-way hashes, not in plaintext.
API key controls
API keys are generated from cryptographically secure random values and stored as hashes. They can be disabled, can have an expiry date, and are checked against the customer organization.
Time-limited downloads
Attachment access uses time-limited signed download links. Production Outlook API responses allow credentials only for an explicit origin allowlist.
Your content is used to provide the service, not to train models
HaulStory processes customer content to provide the service and under the customer’s instructions. HaulStory and OpenAI do not use customer content for model training.
Customers can request deletion of their email, documents, and extracted transport data under the agreed process. Timing and scope are agreed with each customer. Retention, subprocessors, international transfers, and privacy rights are explained in the Privacy Notice.
Established providers support the service
HaulStory uses established providers for hosting, databases, document storage, email delivery, background processing, and AI processing. The service uses encrypted connections.
The Privacy Notice lists the active providers and the safeguards used when data is processed outside the EEA.
Security questions
For a security questionnaire, a question about HaulStory’s controls, or a suspected vulnerability, email contact@haulstory.ai with “Security” in the subject line.
Ask a security question