IT & Security Onboarding

A reference for municipal and county IT departments evaluating Motrix Cloud for a fleet or paratransit maintenance shop. This guide describes the documented application and deployment model. Confirm the deployed version and hosting controls with Motrix during your review.

Current release

These guides reflect Motrix Cloud v2.15.1, released September 9, 2026, including Fleet Readiness, defect verification before return to service, driver qualifications, and assignment safety checks.

For IT reviewers

Motrix Cloud is a zero-install, browser-based SaaS platform. There is nothing to package, no agent to install, and no inbound firewall change required. This page is written to answer a standard vendor security review upfront — if your office uses a security questionnaire or vendor-onboarding form, we will complete it. Contact sales@motrix.io.

1. Architecture & Deployment

2. Network Surface (for whitelisting)

Motrix communicates outbound only over HTTPS. No inbound ports, VPN tunnels, or firewall rule changes are required. The documented browser endpoint is below. Confirm any additional domains and mail-sender settings during onboarding:

Endpoint Purpose Direction / Port
app.motrix.io Primary application Outbound 443
notifications@motrix.io Email sender to whitelist (authenticated SPF/DKIM) Inbound email
Ports

Port 443 (HTTPS) only. Port 80 redirects to 443. No other ports are used.

3. Security & Data Handling

For a deeper security overview, including infrastructure hardening and independent assessment, see the Security Overview.

4. Browser & Device Support

Mobile Device Management (Jamf / Intune)

There is no native app to package. For browser access, push a Web Clip or home-screen shortcut to https://app.motrix.io. No MDM app deployment or app-store review is required.

5. Audit Readiness

DVIR inspections in Motrix are photo-verified, signed, timestamped, and immutable once filed — they cannot be edited or deleted after submission, and that guard is enforced at the data layer rather than by the absence of an edit button. This produces a defensible record suitable for FTA triennial reviews, and the export format supports FDOT audit requirements.

For a per-vehicle evidence bundle, an authorized manager can generate a vehicle audit packet: a ZIP with an evidence-index PDF (inspection items, signatures, measurements, defect resolution, maintenance, work orders, and an attachment manifest) plus the private attachments that are available. Packets cover up to one year, 500 records, and 50 MB of attachments; missing or inaccessible attachments are listed explicitly. Packet generation requires fleet-management and report permissions and is access-logged. A packet is supporting evidence, not a compliance certification.

6. Handling Rider PHI (if applicable)

If your workflow involves rider PHI, review the deployment with your privacy officer before entering data. The HIPAA environment is paused and is not accepting PHI onboarding. The documented privacy options are:

The BAA

Before PHI onboarding can resume, Motrix must reactivate and verify the hosting controls, execute the agency BAA, complete a Security Risk Assessment, test backup restoration, and remove demo data and known-credential accounts. Contact us to review those prerequisites; the standard-tier trial is not a substitute.

7. Verification & Next Step

Whatever next step is most efficient for your team:

Confirm the above is sufficient to proceed, send us your security questionnaire, or book a short technical call — email sales@motrix.io. If additional documentation is required from our side, tell us what is needed; we would rather provide complete information upfront than cause delays.