Trust & Security
X3 SOP · Effective October 4, 2026 · Operated by X3 Fleet Safety LLC
X3 Fleet Safety LLC builds fleet-safety and DOT-compliance software for motor carriers. Because our customers entrust us with regulated driver and applicant data, security and lawful data handling are core to the product. This overview summarizes our program for prospective customers, partners, and their insurers.
Security program
Our program is designed to meet the FTC Safeguards Rule (16 CFR Part 314) and includes:
A designated qualified individual accountable for information security.
Periodic risk assessments covering confidentiality, integrity, and availability.
Encryption of customer information in transit and at rest.
Role-based access controls and multi-factor authentication for administrative access.
Secure development and testing for applications used to transmit, access, or store customer information, including our AI integration.
Activity logging and monitoring.
Written incident-response and breach-notification procedures.
Service-provider selection, contractual safeguards, and ongoing oversight.
Secure data disposal on a defined schedule.
Regulated-data handling
We apply purpose limitation and data minimization to FCRA background data, DPPA motor-vehicle records, and 49 CFR Part 40 DOT testing information. Testing information is treated as confidential and access is restricted to authorized recipients.
Artificial intelligence and sub-processors
Some features use a third-party large-language-model provider. We minimize or redact regulated identifiers and Part 40 content before external processing where feasible, and we process regulated data with that provider only under terms that prohibit training on our data. Our current sub-processor list is in our Data Processing Addendum.
Data residency and continuity
Customer data is hosted with a major U.S.-based cloud infrastructure provider. Our production databases support point-in-time recovery so that service can be restored after an outage or error.
Breach notification
On confirmation of a security incident affecting personal information, we notify affected customers without undue delay, and within 72 hours of confirming it, and cooperate on required regulatory notifications, including notification to the FTC where an incident involves the unauthorized acquisition of unencrypted customer information of 500 or more consumers.
Compliance posture
FTC Safeguards Rule: program aligned as described above.
Reporting a vulnerability
Please report suspected vulnerabilities to [email protected]. We investigate all good-faith reports.
Trust & Security · Privacy Policy · Terms of Service · Questions? [email protected]