Skip to content
All Systems Operational

SECURITY & COMPLIANCE / V4.2 / UPDATED 14 MAR 2025

SOC 2 Type II fleet software, audited continuously since 2021.

AutoNav 2000 is the operations layer for 1,847 fleets and 142,000+ vehicles. Before you book a demo, the platform’s security posture has to clear procurement, IT-security, and the European DPO — so this page is structured to answer the questionnaire first, not after a sales call.

  • 01 / UPTIME / TRAILING 24 MONTHS 99.971%

    Measured across all production tiers, weighted by request volume.

  • 02 / SOC 2 TYPE II TENURE 4 yrs

    Continuously audited since 2021. Most recent report: Q4 2024.

  • 03 / ISO 27001 3 yrs

    Recertified annually. Surveillance audit: 12 Feb 2025.

  • 04 / MULTI-HOUR INCIDENTS 0

    Since January 2023. Every minute published to the public status page.

§01 / CERTIFICATION MATRIX

Four governed programs, not a badge wall.

Each program below is a live, repeatable audit cycle — not a one-time screenshot. Scope, governing body, and most recent attestation date are listed so they can be pasted straight into a vendor risk assessment.

  1. 01

    SOC 2 Type II

    TRUST SERVICES CRITERIA · SECURITY, AVAILABILITY, CONFIDENTIALITY
    ISSUER
    Independent CPA firm (Schellman & Co., LLC)
    WINDOW
    12-month observation period, rolling
    LAST REPORT
    12 Dec 2024 — bridge letter refreshed Q1 2025
    RENEWAL CADENCE
    Annual, with quarterly bridge letters on file
    SCOPE
    AutoNav 2000 routing engine, dispatch console, telematics integrations, supporting AWS & GCP infrastructure
    DELIVERABLE
    Full report under NDA — request via the security pack link below
  2. 02

    ISO 27001

    INFORMATION SECURITY MANAGEMENT SYSTEM / ISMS
    CERT BODY
    BSI Group America, Inc.
    CERTIFICATE NO.
    IS 776421
    INITIAL ISSUE
    14 Mar 2022
    LAST RECERTIFICATION
    12 Feb 2025 (surveillance audit passed, zero non-conformities)
    STATEMENT OF APPLICABILITY
    Rev 4.1, 117 Annex A controls assessed
    DELIVERABLE
    SoA & certificate available on request under NDA
  3. 03

    GDPR & EU Data Protection

    REGULATION (EU) 2016/679 · DPA 2018 (UK)
    LEAD DPA
    CNIL (France) — EU representative; ICO (UK)
    LAWFUL BASIS
    Article 6(1)(b) contract performance; 6(1)(f) legitimate interest for telemetry
    DPA / SCCs
    EU SCCs (2021/914) executed with all sub-processors; UK Addendum in place
    TRANSFER MECHANISM
    EU-US DPF (self-certified) + SCCs + supplementary measures; UK extension active
    DPIAs
    On file for telematics processing, driver behaviour scoring, and route analytics
    LAST DPO REVIEW
    Q4 2024 — no outstanding regulator action
  4. 04

    EU Data Residency

    PRODUCTION REGIONS · FRANKFURT & DUBLIN
    PRIMARY REGION
    eu-central-1 (Frankfurt, DE) · AWS
    SECONDARY REGION
    eu-west-1 (Dublin, IE) · AWS
    FAILOVER
    Warm-standby, RPO 60 s · RTO 4 min measured
    SOVEREIGNTY
    Customer data never leaves selected region — verified by quarterly egress audit
    SUB-PROCESSORS
    AWS (hosting), Cloudflare (egress), Stripe (billing only — outside routing tier)
    REQUEST
    Full sub-processor list & residency amendment via the security pack link

§02 / REGION SPECIFICATION

EU data residency, specified like a region — not marketed like a feature.

For customers that route vehicles inside the EEA and UK, AutoNav 2000 runs entirely inside the chosen region. Below are the operational parameters procurement and platform-engineering teams typically need before signing a data processing addendum.

EU-CENTRAL-1

Frankfurt — primary EU region

Frankfurt am Main, Germany · AWS infrastructure · operated by AutoNav 2000 EU GmbH.

LATENCY TO DACH FLEET HUBS
Berlin 14 ms · Munich 9 ms · Hamburg 17 ms · Vienna 18 ms · Zurich 22 ms
FAILOVER TARGET
eu-west-1 (Dublin), warm-standby, RTO 4 min
ENCRYPTION
AES-256 at rest · TLS 1.3 in transit · KMS keys held in Frankfurt, customer-managed via BYOK add-on
SUB-PROCESSORS
AWS (hosting) · Cloudflare (egress only) · Stripe (billing, isolated)
LOG RETENTION
Hot 30 d, warm 12 mo, cold 24 mo — all stored in-region
SELECTION
Onboarding form, default for DE / AT / CH / NL / PL / CZ
REQUEST SUB-PROCESSOR LIST →
EU-WEST-1

Dublin — secondary EU region & UK adjacency

Dublin, Ireland · AWS infrastructure · chosen for low-latency UK & Nordics coverage.

LATENCY TO UK & NORDICS
London 11 ms · Manchester 16 ms · Amsterdam 14 ms · Stockholm 24 ms · Oslo 27 ms
FAILOVER TARGET
eu-central-1 (Frankfurt), warm-standby, RTO 4 min
ENCRYPTION
AES-256 at rest · TLS 1.3 in transit · KMS keys held in Dublin, BYOK available
SUB-PROCESSORS
AWS (hosting) · Cloudflare (egress only) · Stripe (billing, isolated)
LOG RETENTION
Hot 30 d, warm 12 mo, cold 24 mo — all stored in-region
SELECTION
Onboarding form, default for UK · IE · SE · NO · DK · FI
REQUEST DPA / SCC ADDENDUM →

§03 / SECURITY OPERATIONS — ANSWER FIRST

How the platform is actually defended.

The four mechanisms below are what an IT-security lead needs to copy into a vendor risk questionnaire. Everything else on this page is supporting evidence.

01 / ENCRYPTION

Data is encrypted at rest, in transit, and in use.

All customer data is protected with AES-256 at rest and TLS 1.3 in transit. Per-region KMS keys are held inside the chosen EU region; customers on the Enterprise tier may supply their own keys (BYOK) via AWS KMS or HashiCorp Vault. Searchable fields use deterministic encryption with per-tenant keys rotated quarterly. Backups are encrypted with envelope encryption and stored in the same region as the primary database.

02 / ACCESS CONTROL

Least-privilege, SSO-enforced, and quarterly access reviews.

Every employee with production access authenticates through Okta SSO with hardware-key MFA (YubiKey 5, FIDO2). Production access is granted via short-lived (8-hour) sessions brokered through Teleport; standing access is removed at quarter end. Customer tenant access follows the same model — role-based permissions, SSO/SAML, IP allowlists on request, and break-glass access that pages the on-call security engineer and writes an immutable audit log entry.

03 / DETECTION & RESPONSE

24/7 detection, on-call response, and customer-visible incidents.

Security signals from the platform, infrastructure, and identity providers stream into a SIEM (Datadog Cloud SIEM) with detections maintained by an in-house detection engineering team. Critical alerts page the on-call security engineer through PagerDuty. Confirmed security incidents trigger customer notification within 72 hours per our SOC 2 availability and confidentiality commitments, and within 24 hours for personal-data breaches per GDPR Article 33.

04 / TRANSPARENCY

Public status page, audit reports on request, and zero mystery outages.

Every production incident — including incidents with zero customer impact — is published to status.autonav2000.com with timeline, root cause, and remediation. The page has 36 months of uptime history and zero multi-hour incidents since January 2023. SOC 2 Type II reports, ISO 27001 statements of applicability, penetration-test executive summaries, and sub-processor lists are available under NDA from the request below.

PEN-TEST CADENCE — ANNUAL BY NCC GROUP · LAST 19 NOV 2024 · BUG-BOUNTY VIA HACKERONE

VULN DISCLOSURE — [email protected] · PGP KEY ON /SECURITY/

§04 / UPTIME & THROUGHPUT RECORD

36 months of uptime, dated and downloadable.

Every number below is published, timestamped, and linkable to the public status page. If a procurement officer wants to verify it, they can.

  • UPTIME / 36-MO ROLLING 99.974%

    Aggregate across all production tiers, weighted by request volume. View raw history →

  • MULTI-HOUR INCIDENTS SINCE JAN 2023 0

    The threshold is any production-impacting outage longer than 60 minutes. We have not crossed it.

  • P95 ROUTING RESPONSE / STANDARD TIER <180 ms

    Measured across 9.4 billion routing decisions processed in the trailing 12 months.

  • ROUTING DECISIONS / TTM 9.4 B

    Production telemetry aggregated from the platform’s internal metrics — not a marketing estimate.

§05 / CLOSING MOTIONS

Two ways to clear security review.

Procurement moves at two different cadences. Pick the one that matches where you are this week — both paths reach the same fleet solutions engineer.

PATH A

Book a live demo with a fleet solutions engineer.

For evaluators who already have sign-off on security and want to see the dispatch console, telematics integrations, and routing engine on real data. 30 minutes, screen-shared, no sales script.

  • — Includes a walkthrough of the SOC 2 / ISO 27001 evidence folder.
  • — Available in English or German; EU-region demos hosted on Frankfurt infrastructure.
  • — Direct line to the routing-engineering team for technical questions.
BOOK A LIVE DEMO →
PATH B

Request the security pack under NDA.

For evaluators who need the SOC 2 Type II report, ISO 27001 statement of applicability, latest penetration-test summary, sub-processor list, and DPA / SCC addendum before opening a sales conversation.

  • — Delivered within one business day by the security team — no sales gating.
  • — Mutual NDA template attached to the request; redlines supported.
  • — Escalation path to the CISO direct line for unresolved findings.
EMAIL [email protected] →

DIRECT · [email protected] · +1 (312) 555-0482 · 440 W Randolph Street, Suite 620, Chicago, IL 60606

EU OFFICE · AutoNav 2000 EU GmbH, Mainzer Landstraße 178, 60327 Frankfurt am Main, Germany