Security
Your carrier list is the business. Here is exactly where it sits.
A dispatch house’s carrier list, its rates and its conversation history are the whole asset. You are entitled to a straight answer about where they live and who can reach them, so this page gives one — including the parts that are not perfect.
Separation
One workspace per customer, not one database with a column for you
Your own container
Every customer gets a separate application with its own disk and its own database. There is no shared table of carriers with a customer id on each row, so there is no query that could return somebody else’s.
Your own mailbox
Email leaves from a mailbox you own, using credentials you supply. We do not relay your mail through a shared sender, so your reputation is yours and nobody else’s sending affects it.
Your own AI key
You add your own Anthropic key. Your prompts and replies go from your container to them, on your account — not pooled through ours.
Credentials are encrypted at rest
Mailbox passwords and tokens are encrypted with a key that lives on your container. Sign-in passwords are hashed, not encrypted — they cannot be turned back into a password by anyone, including us.
Inside your team
What one of your people can and cannot do
| Owner | Admin | Operator | Viewer | |
|---|---|---|---|---|
| Work carriers, read replies | ✓ | ✓ | ✓ | read only |
| Connect their own AI sales agent | ✓ | ✓ | ✓ | — |
| See another person’s report | ✓ | — | — | — |
| Change company settings | ✓ | ✓ | — | — |
| Add or remove teammates | ✓ | ✓ | — | — |
| Read anybody’s password | never | never | never | never |
Nobody — not the owner, not us — can read a teammate’s password. An invitation is a single-use link that person redeems themselves, and they choose what they type.
Being straight
What we can see, honestly
We do not read your carriers to run the service
Nothing in the product sends your carrier list or your conversations to us. The billing side knows who you are, what plan you bought and when it ends — and nothing about who you are emailing.
But we host it, and that means something
We run the servers, so with access to the hosting account a person on our side could reach a container. We are not going to pretend a hosted product is one we cannot technically touch. What we can tell you is that nothing in the software does it, and that access is limited to the people who keep it running.
If you park your workspace, we hold a copy
When a customer stops and asks us to keep their data, an archive of it sits on our side so it is waiting when they come back. It carries no passwords and no keys, but it does carry carriers and history. If you would rather we did not keep one, say so and we will delete instead.
Leaving takes your data with you
Ask and we will export your workspace — carriers, conversations, the lot. There is no exit fee and no notice period, because a product that has to trap you is not one worth selling.
Sending
The rules the software keeps for you
An opt-out on every message
Added automatically, and a carrier who uses it is not written to again.
Your US company’s address on every message
Commercial email into the United States requires a real postal address, and it has to belong to the company the carrier is dealing with — your US entity, not wherever your desk happens to be. FleetIQ refuses to save one that is not a US address, so it cannot be got wrong quietly.
Paced sending, inside your hours
Gaps between sends, a daily ceiling per mailbox, and outreach only inside the window you set — so a new mailbox is not burned in its first week.
It never claims to be a dispatcher
The agent sells your dispatch team. A draft that says otherwise is rejected before it can be sent.
It never promises what it cannot do
A specific commitment it has no authority to make — a rate, a call at a time nobody agreed — is caught and rewritten.
No tracking pixel unless you turn it on
Off by default. Remote images cost inbox placement, and most opens are not real opens anyway.
The full detail
What is collected, where it is processed, how long it is kept and how to get it deleted is all in the privacy policy — in plain language, not in a wall of definitions.