FK Command Center ← Back to FK

Security at FK Command Center

You're trusting us with your fleet, your income, and your tax position. Here's exactly how we protect it — in plain language, no marketing fog.

Last updated: 2026-06-19 · Operated by Firstkontak Consultant Inc, San Diego, CA

Encrypted everywhere

TLS/HTTPS in transit, encryption at rest in the database and file storage.

Your data is isolated

Row-Level Security and per-license access — your records are reachable only with your key.

We never touch your card

Payments run entirely through Stripe. We never see or store card numbers.

We don't sell your data

No data sales, no cross-web ad tracking. Ever.

How your data is protected

Encryption in transit and at rest

Every connection to FK Command Center is served over HTTPS/TLS, enforced with HSTS so browsers refuse to downgrade to an insecure connection. Your fleet, trip, maintenance, claim, and tax data is stored encrypted at rest in our managed Postgres database (Supabase). Uploaded files — invoices, receipts, photos — are stored in private, encrypted object storage.

Strict data isolation

Row-Level Security (RLS) is enabled on every table that holds your data, with a default-deny posture: a database key exposed to the browser can read nothing. All reads and writes flow through our application server, which authorizes each request against your specific license before returning a single byte. Uploaded files are served only through short-lived signed URLs scoped to your account, and every file path is ownership-checked on access.

Authentication built to resist attacks

Secure payments and integrations

Checkout and billing are handled by Stripe, a PCI-DSS Level 1 certified provider. Card data never reaches our servers. Incoming events from Stripe and our email provider are cryptographically signature-verified before we act on them, so forged webhooks are rejected.

Privacy by default

How we keep it secure over time

Your controls

You can…How
Export everything you've enteredSettings → Backup (full JSON download)
Permanently delete your account & dataSettings → Delete Account (one click; reversible from backups for 30 days, then permanent)
Opt out of benchmark sharingSettings → Data Sharing (off by default)
Exercise CCPA / GDPR rightsEmail us — see below

Sub-processors

A short, vetted list of providers helps run the product. Each is contractually bound not to use your data for their own purposes.

ProviderPurpose
StripePayment processing (PCI-DSS Level 1)
SupabaseEncrypted database & private file storage
RailwayApplication hosting
ResendTransactional email (license keys, verifications)
SentryError monitoring (credentials scrubbed)
OpenRouterAsk FK answers only — per question, not retained

Responsible disclosure

Found a security issue? We want to hear from you, and we won't pursue good-faith researchers who follow this policy. Please email security@firstkontakconsulting.com with steps to reproduce, and give us a reasonable window to fix it before any public disclosure. Avoid privacy violations, data destruction, and service degradation while testing.

Honest scope. FK Command Center is operated by a small, focused team. We apply enterprise-grade controls — encryption, data isolation, signed payments, automated scanning, and incident response — but we are not currently SOC 2 certified. If your organization requires a formal report, a security questionnaire, or a Data Processing Agreement, email security@firstkontakconsulting.com and we'll work with you.

See also our Privacy Policy and Terms of Service.