Skip to main content

Security at HaulStory

HaulStory processes transport email and documents to build source-backed timelines. This page explains the practical controls used to protect that data.

Last reviewed: 21 September 2026

Access is authenticated and scoped to your organization

User access is limited to the organizations a person is authorized to use. Passwords and API credentials are not stored in plaintext, and document download links expire after a limited time.

  • Organization-scoped access

    User access is authenticated and limited to the organizations a person is authorized to use. Super-admin operations require a separate authorization check.

  • Hashed credentials

    User passwords and API credentials are stored as one-way hashes, not in plaintext.

  • API key controls

    API keys are generated from cryptographically secure random values and stored as hashes. They can be disabled, can have an expiry date, and are checked against the customer organization.

  • Time-limited downloads

    Attachment access uses time-limited signed download links. Production Outlook API responses allow credentials only for an explicit origin allowlist.

Your content is used to provide the service, not to train models

HaulStory processes customer content to provide the service and under the customer’s instructions. HaulStory and OpenAI do not use customer content for model training.

Customers can request deletion of their email, documents, and extracted transport data under the agreed process. Timing and scope are agreed with each customer. Retention, subprocessors, international transfers, and privacy rights are explained in the Privacy Notice.

Established providers support the service

HaulStory uses established providers for hosting, databases, document storage, email delivery, background processing, and AI processing. The service uses encrypted connections.

The Privacy Notice lists the active providers and the safeguards used when data is processed outside the EEA.

Security questions

For a security questionnaire, a question about HaulStory’s controls, or a suspected vulnerability, email contact@haulstory.ai with “Security” in the subject line.

Ask a security question
Security at HaulStory | HaulStory