Tooli Logistics LLC operates Axivoy TMS. This page is a public overview of how we approach product security and how to report vulnerabilities. It is not an internal runbook and does not disclose infrastructure diagrams or exploit detail.
How we protect the service
- Tenant isolation — shared-schema, row-scoped tenancy so customer data stays separated by organization.
- Access control — role-based permissions for admin, dispatcher, driver, and accountant workflows.
- Transport security — production traffic is served over HTTPS (TLS) at the edge.
- Secrets — sensitive integration credentials (including bank-link access tokens) are encrypted at rest in the application where stored.
- Auditability — state-changing operations write to an append-only audit trail.
- Dependency hygiene — we review dependency and code-scanning signals on a regular cadence and patch according to severity.
Bank linking
Bank account linking for receivables uses Plaid Link in the authenticated admin web UI. Operators acknowledge our Privacy Policy and Data retention summary before Link opens; acknowledgments are audited with user, tenant, timestamp, and policy version.
Vulnerability disclosure
If you believe you have found a security issue in Axivoy, please email security@toolilogistics.com (monitored alias) or meesam@toolilogistics.com.
Please include:
- A clear description of the issue and potential impact
- Steps to reproduce (or a proof-of-concept) when possible
- Whether you believe tenant data, bank-link tokens, or authentication are affected
Do not include production credentials, customer bank payloads, or personal data beyond what is needed to demonstrate the issue. Please give us a reasonable window before public disclosure. We will acknowledge receipt and work with you on remediation timing.