The product's whole premise is a number your finance team can trust, that only works if the data handling underneath is just as disciplined. Here's how we treat yours.
Data protection
All traffic encrypted in transit (TLS); data encrypted at rest on AWS infrastructure
Strict per-fleet workspace isolation, one fleet's data is never visible to, or pooled with, another's
Card transaction data is used solely to verify fill-ups and compute savings, never resold, never used for advertising
No personal payment credentials, ever: TopOff has no personal card numbers to lose
Access & operations
Least-privilege production access, limited to the founding team, behind SSO with short-lived credentials
Every posted savings figure is auditable end-to-end via its card transaction ID
Error monitoring and alerting on all production services
Serverless architecture (AWS Lambda + DynamoDB), no long-lived servers to patch or forget
Driver privacy by design
Location is used only while the app is open, no background tracking, no location history profiles
No personal accounts or personal cards; drivers exist only inside the fleet's workspace
No advertising or cross-app tracking SDKs in the app