Security
Report integrity is treated as a product feature.
VerifGo is built around a simple idea: once a daily verification report is submitted, the record should be clear, controlled, and resistant to casual tampering.
Security controls in the product direction
- Submitted reports are designed to stay immutable after submission.
- Server-side submitted timestamps and integrity hashing are part of the report-hardening direction.
- Driver access is designed around least-privilege rules, including row-level security for driver-owned records.
- Audit and smoke-test workflows are used to catch regressions before release decisions.
Clear boundaries
- Security posture does not mean regulator approval.
- VerifGo does not create backdated or fake reports.
- The wider pilot waits for remote trust closure and owner review.
Current readiness
The MVP has passed local hardening work, and the next gate is remote trust closure before a wider pilot. That gate exists so the public product can earn trust through evidence, not marketing language alone.