Security at Motrix Cloud
Protecting fleet data for Florida paratransit and government agencies
Motrix Cloud is purpose-built for Florida paratransit and government fleet agencies. Security and data protection are not afterthoughts — they are foundational to every layer of the platform, from infrastructure to application design.
Handling rider PHI? The Motrix HIPAA tier adds a signed Business Associate Agreement, dedicated single-tenant hosting, mandatory two-factor authentication, and a 6-year rider-record access log. See the HIPAA & rider-data compliance page for details.
Security Assessment
Motrix Cloud undergoes regular structured security assessments using OWASP Top 10 and NIST guidance. A formal third-party penetration test was conducted in March 2026 following OWASP Testing Guide v4.2 methodology. The assessment returned an overall risk rating of LOW, and all critical findings have been remediated.
- Overall risk rating: LOW, with all critical findings remediated
- Multi-tenant data isolation verified across tenant boundary controls
- Most recent assessment: formal third-party penetration test, March 2026 (OWASP Testing Guide v4.2)
Infrastructure & Application Security
- Encryption in transit: TLS 1.3 with HSTS enforcement on all connections
- Security headers: All 6 recommended security headers deployed, including Content-Security-Policy and X-Frame-Options
- CSRF protection: Token-based protection on all forms and state-changing requests
- Access control: Role-based access control (RBAC) with per-agency tenant isolation
- Inspection integrity: DVIR inspection records are immutable once submitted (FTA compliance)
- Rate limiting: Logins limited to 10 attempts per minute; password reset emails rate-limited to prevent abuse
- Export safety: All CSV exports are sanitized against formula injection
- Registration control: Public registration is disabled; users are added via trial signup or invitation
- API surface: No publicly exposed API endpoints; integrations available on request via authenticated channels
- Session security: Cookies set with HttpOnly, Secure, and SameSite attributes
Hosting & Data Residency
- Hosting provider: DreamHost, a US-based infrastructure provider
- Data residency: All customer data is stored on US-based infrastructure
- No offshore processing: Customer data is not replicated or processed outside the United States
Backups & Recovery
- Backup frequency: Daily automated backups
- Retention: 30-day rolling retention window
- Encryption at rest: All backup data is encrypted at rest
- Restore validation: Restore process has been tested to confirm recoverability
Request Full Report
The complete security assessment report is available under NDA. Contact us to request a copy.
Request Security ReportLast updated: June 2026