Security and data handling.
A brokerage’s records are its customers, its carriers and its prices. This page says plainly how CarShipDesk keeps them, who can reach them, and what is logged.
- Sign-in
- Sign-in runs through WorkOS AuthKit. CarShipDesk never sees or stores a password. Access is by invitation from an owner.
- Tenancy
- Every organization is a tenant. Every row in the database carries its organization and row-level security enforces the boundary in the database itself, so a bug in the application cannot read across it. Each brokerage also has its own address on its own subdomain.
- Roles and grants
- Three roles set defaults. Features are granted per person on top of the role, with an optional expiry. The API enforces the same rule the screen shows; hiding a menu is never the security.
- Audit log
- Grant changes, session actions, stage commands, settings changes, payments and exports are written with who and when, and the before and after where it applies. Owners and managers can read the log.
- Sessions
- Each person has a list of active sessions with device, browser and IP address. Owners, and managers the owner permits, can end one session or all of them.
- Load-board writes
- Central Dispatch and Super Dispatch connect through your own board accounts. Posting from CarShipDesk is not live yet; when it ships, writing stays off per board until the owner authorizes it in writing. The default is off.
- Exports
- Reports, analytics, hours and statements download as CSV for people granted export, and each download is written to the audit log with who ran it. A full export of every record is not built yet.
- Card data
- CarShipDesk never stores a card number. Card entry happens on the payment processor's hosted page; CarShipDesk keeps the processor's reference and the result.
- Broker neutrality
- CarShipDesk does not run a brokerage, does not sell leads and does not share one brokerage's records, carriers or prices with another.
What is not yet in place
The session list, end-session actions and approval rules described above are live. Not done yet: an independent application-security review, a documented backup-restore drill, and organization settings for two-factor sign-in, a single-session rule and an IP allowlist. We say so here rather than imply otherwise.
Questions about a specific control, or a questionnaire from your insurer: write to hello@carshipdesk.com. The terms of service, privacy policy and data processing addendum set out these commitments in writing.
Ask us anything on this page.
Owners of pilot brokerages talk to the people who built the access model, not to a sales queue.