Haultro Security. Enterprise-grade security architecture for waste management software. Haultro by Viceroy NM provides multi-tenant data isolation at the database level with organization-scoped queries on every request. JWT-based authentication with embedded role claims enforces 5 distinct permission levels (Admin, Manager, Driver, Client, Enterprise Admin) across 150 plus API endpoints. WebSocket real-time connections use Socket.IO room-based architecture scoped to organization ID for complete event isolation. AI safety guardrails include input sanitization, iteration limits, and role-based tool restrictions for the Haultro AI Chat. IoT sensor endpoint authenticates device identity before accepting readings. All data in transit encrypted with TLS and HTTPS. PostgreSQL database with 20 plus relational tables and organization-level data isolation. Redis for session management and high-throughput IoT ingestion buffering. Containerized deployment with 7 interconnected services. Stripe PCI-compliant payment processing. Haultro never stores credit card data. AI provider communications with Anthropic Claude, OpenAI, and Google use encrypted channels under commercial API terms with no customer data used for model training. Platform-wide audit logging captures every action across every organization for compliance-grade audit trails.
Your data is your business. We protect it.
Multi-tenant data isolation. Role-based access control. Encrypted communications. Platform-wide audit logging. Security built into the architecture from day one, not bolted on after launch.
Five layers between a request and your data.
Every API call passes through five sequential security checks before it ever touches your data. Watch a request flow from edge to database below.
Three pillars hold up the platform.
Data isolation. Access control. Audit and compliance. Each pillar is enforced at multiple layers, from the database query up to the API edge.
Data Isolation
Complete tenant isolation at the database level. Every query is scoped to the authenticated user's organization. Cross-organization data access is architecturally impossible for standard users. Only authenticated Enterprise Admins can perform cross-org queries, and only through the Portfolio Intelligence module.
Access Control
JWT-based authentication with role claims enforced on every API request. Five distinct permission levels (Admin, Manager, Driver, Client, Enterprise Admin) each with precisely scoped access to endpoints, data, and features. 150 plus endpoints all enforce org membership and role validation.
Audit and Compliance
Platform-wide audit logging captures every action across every organization. User actions, API calls, configuration changes, and data access are all timestamped and immutable. Enterprise operators get compliance-grade audit trails exportable for regulatory reviews and internal governance.
Identity and access management.
Every request to the Haultro platform is authenticated, authorized, and scoped. There are no anonymous endpoints for operational data. The security model validates three layers on every API call: identity (who you are), organization (which tenant), and role (what you are allowed to do).
WebSocket and API protection.
Real-time features use WebSocket connections with room-based architecture. Users are automatically placed in their organization's room and only receive events from that room. The AI Chat includes additional guardrails to prevent prompt injection and system abuse.
Production-grade infrastructure.
The technology stack underneath every feature. Each service is isolated, encrypted, and monitored. Each integration is hardened.
PostgreSQL
20+ relational tables with org-level isolation. Foreign keys and indexes enforce data integrity end-to-end.
Redis
In-memory caching for sessions, real-time data layers, and high-throughput IoT ingestion buffering.
Socket.IO
WebSocket connections with room-based architecture for org-scoped real-time events. Auto reconnection and fallback.
HTTPS / TLS
All data in transit encrypted with TLS. API endpoints, WebSocket connections, and client portals all over HTTPS.
Containerized
Fully containerized deployment with 7 interconnected services. Isolated runtime environments for API, workers, and real-time.
Stripe Payments
Payment processing via Stripe with PCI-compliant infrastructure. Haultro never stores credit card data.
AI Provider Security
Encrypted channels to Anthropic, OpenAI, and Google under commercial API terms. No customer data used for model training.
Audit Logging
Every action across every org logged with timestamp, user ID, action type, and affected resources. Exportable for compliance.
Security questions, answered.
What customers ask before they trust us with their operations.
Is my organization's data isolated from other customers?
How does role-based access control work?
Is data encrypted in transit and at rest?
Does Haultro use my data to train AI models?
What happens to my data if I cancel my subscription?
Can I export my data?
Have specific security requirements?
Our team can walk you through the platform's security architecture in detail, answer compliance questions, and discuss custom security requirements for enterprise deployments.