Real isolation, real encryption, real access controls — not a marketing checklist. Here's exactly what protects your loads, carriers, customers, and financial records today.
Every table is scoped to your company at the data-access layer, not a shared database with a filter bolted on top. No other company on the platform can ever see your loads, carriers, customers, documents, or financial records.
All traffic runs over HTTPS/TLS. Uploaded documents are encrypted at rest — not stored as plain files on disk for anyone with server access to read.
Real MFA, not a checkbox: authenticator-app (TOTP) codes, recovery codes, trusted devices, and email one-time codes — with an admin-forced reset path if someone loses their device.
Every document, logo, and carrier-upload-link file is scanned before it's stored. If the scan can't be completed, the upload is rejected — never silently allowed through unchecked.
Granular permissions for Owner, Admin, Dispatcher, Broker, Accounting, and more — with custom roles available on Business and Enterprise plans, so access matches exactly what each person on your team should be able to touch.
Platform-administrative actions are tracked in an audit log — a real record of who changed what, not just an assumption that nothing goes wrong internally.
Passwords are hashed with bcrypt — never stored in plain text, never reversible, and every login attempt is rate-limited against brute-force guessing.
Every state-changing request — creating a load, updating an invoice, changing a setting — is protected against cross-site request forgery, not just the login form.
Live FMCSA SAFER lookups on every carrier profile — operating authority, insurance filing status, and safety rating, checked at the point of booking, not assumed from a document uploaded months ago.
Yes. BZ Loader is multi-tenant by design from the ground up — every table is scoped to your company at the data-access layer, not a shared database with a filter added on top. No other tenant can see your loads, carriers, customers, or financial records.
Yes. All traffic is encrypted in transit over HTTPS/TLS, and uploaded documents are encrypted at rest.
Yes — real MFA including authenticator-app (TOTP) codes, recovery codes, trusted devices, and email one-time codes, with admin-forced reset if a device is lost.
Yes. Every document, logo, and carrier-upload-link file is scanned before it's stored, and the upload is rejected if the scan can't be completed rather than allowed through unchecked.
Reach out and we'll work through it directly — we'd rather answer a specific question honestly than make you guess from a marketing page.
Contact UsCreate your company account and start posting loads in minutes. No credit card required to start your trial.
Start Free Trial