Security

Report integrity is treated as a product feature.

VerifGo is built around a simple idea: once a daily verification report is submitted, the record should be clear, controlled, and resistant to casual tampering.

Security controls in the product direction

  • Submitted reports are designed to stay immutable after submission.
  • Server-side submitted timestamps and integrity hashing are part of the report-hardening direction.
  • Driver access is designed around least-privilege rules, including row-level security for driver-owned records.
  • Audit and smoke-test workflows are used to catch regressions before release decisions.

Clear boundaries

  • Security posture does not mean regulator approval.
  • VerifGo does not create backdated or fake reports.
  • The wider pilot waits for remote trust closure and owner review.

Current readiness

The MVP has passed local hardening work, and the next gate is remote trust closure before a wider pilot. That gate exists so the public product can earn trust through evidence, not marketing language alone.