Home / Security
How FreightScout handles your brokerage data
FreightScout keeps each brokerage's operational data scoped to that brokerage, encrypts connected mailbox tokens, and runs the product supervised by default. The application and this website are hosted on Vercel. The database and authentication are hosted on Supabase. The full policy, including retention and the processor list, is the privacy and messaging policy.
Last updated 20 September 2026.
How FreightScout works with a TMS is on how FreightScout works with your TMS. Today that is a supervised agent that needs no API. A native API connection is built during onboarding. It is not live today. The product is the platform. Plans are on pricing.
Data handling
Account information, load records, carrier and contact records, lane and rate data, pipeline status, and outreach history are the working data of your brokerage and are scoped to your organization. Product data is used to run the product for that brokerage.
Your load, lane, rate, carrier, margin, and contact data is not used to train generalized AI or machine-learning models. It is not shown, sold, licensed, or made available to any other customer, and it is not pooled with any other customer's data to build a shared model, index, benchmark, or rate product. What the product learns from your data stays scoped to your brokerage.
If you connect Google or Microsoft, OAuth tokens are encrypted at rest with AES-256-GCM. They are decrypted only in memory by the backend. Raw tokens are not written to disk, included in logs, or shown in the product. Encryption keys are held as server environment variables, separate from the database, so a compromise of the database alone does not expose token data. When an administrator deactivates a user, the associated OAuth tokens and email-connection data are deleted.
Gmail content is hidden from FreightScout staff in the normal course of the work. It is read only with your consent for specific messages, when it is necessary for security purposes such as investigating abuse, or to comply with applicable law.
Hosting
Supabase hosts the database and authentication, and it holds product data. Vercel hosts the application and this website. Product data passes through Vercel in transit. Vercel Analytics records aggregate page-view counts on the public site and sets no advertising cookies.
Access control
Database access for the product goes through the backend service key. Row-level security is enforced so each organization sees only its own data. A connected Outlook mailbox copy is stored against that brokerage's organization under the same row-level security, and no other customer can reach it. Security and audit logs of sign-ins, privilege changes, and administrative actions are append-only.
Supervised by default
Build, Cover, Track, and Bill are live and supervised, including invoicing and collections. Booking the carrier and shipper outreach run supervised by default. A broker can switch either to autopilot, per team and per action. Every action is logged and reversible. You still decide which action a team may run without a person in the loop. Check calls, which are one of those supervised jobs, are described on check call automation.
Where the rest of the detail lives
Retention periods, the companies that process a defined slice of data, SMS consent, and the OAuth scopes are in the privacy and messaging policy. This page states the handling, the hosting, the access control, and the supervision default. It does not add a claim the policy does not already make.
Questions people actually ask
Where is FreightScout hosted?
Vercel hosts the application and this website. Supabase hosts the database and authentication. Product data is held in Supabase and passes through Vercel in transit.
Is brokerage data used to train a shared model?
No. Your load, lane, rate, carrier, margin, and contact data is used to run the product for your brokerage. It is not used to train generalized models, and it is not pooled with another customer's data.
Who can see another brokerage's loads?
Row-level security is enforced so each organization sees only its own data. Database access for the product goes through the backend service key.
Are connected mailbox tokens stored in the clear?
No. Google and Microsoft OAuth tokens are encrypted at rest with AES-256-GCM. Keys are held separate from the database. Raw tokens are not written to logs or shown in the product.
Does the work run without a person by default?
No. Build, Cover, Track, and Bill are supervised, including invoicing and collections. Booking and shipper outreach run supervised by default. A broker can switch either to autopilot, per team and per action. Every action is logged and reversible.
Where is the full policy?
The privacy and messaging policy is the full document, including retention, processors, and consent. This page is the short version of what that policy already says about handling, hosting, access, and supervision.
Most freight software watches your business. FreightScout wins freight and then runs it.