LoadOut
PlatformWorkflowPricingSecurity
Sign in
Trust center

Security at LoadOut

LoadOut uses layered identity, authorization, data, and billing controls designed to protect each operations workspace.

Effective July 19, 2026
Report a vulnerability

Send a concise report with reproduction steps and potential impact. Do not include secrets or personal data you do not own.

Email the security team
Security is a shared responsibility.

LoadOut protects the service boundary and provides account controls. Customers remain responsible for assigning appropriate roles, protecting email accounts and devices, enabling available two-factor authentication, and promptly removing access that is no longer needed.

1

Identity and account protection

  • Identity gateway. Cloudflare Access verifies an authorized email identity before the protected application opens.
  • Optional second factor. Users may add authenticator-based two-factor authentication to their LoadOut account.
  • Session controls. Protected requests are tied to authenticated sessions and rejected when identity requirements are not met.
  • Administrative control. Workspace administrators control invitations, membership, and operational roles.
2

Authorization and workspace isolation

LoadOut checks authorization on the server for protected data and actions. Role checks determine whether a User may perform sensitive operations. Records are scoped to the authenticated workspace rather than relying on interface visibility alone.

Sensitive changes generate operational history so teams can identify who performed an action and when. The application treats browser inputs, record identifiers, redirect parameters, and entitlement claims as untrusted and validates them at the service boundary.

3

Data protection

  • Network traffic is protected with HTTPS while moving between a supported browser, Cloudflare, LoadOut, and connected service providers.
  • Structured application data is stored in Cloudflare D1 and accessed through workspace-scoped application controls.
  • Uploaded photographs and evidence are stored in private Cloudflare R2 object storage and delivered through authenticated application requests rather than public object links.
  • Service credentials and signing secrets are kept outside client-side application code and are available only to the server components that need them.

Additional information about personal data, providers, and retention appears in the Privacy Policy.

4

Billing integrity

Stripe hosts payment-card entry, checkout, invoices, and the customer billing portal. LoadOut does not use a browser redirect, plan name in a request, or client-side state as proof of payment.

Paid entitlements change only after LoadOut validates a cryptographically signed Stripe event and matches its subscription and price data to an allowed plan. Billing events are processed idempotently so a retry cannot apply the same event twice. Webhook traffic is isolated from the human sign-in surface and restricted to the expected request shape and trusted provider network.

5

Application and operational safeguards

LoadOut applies validation and explicit state transitions to operational actions such as booking, load verification, returns, cleaning, repair, and quality control. Critical checks are performed by the server so they cannot be bypassed merely by changing browser markup or request fields.

Request paths, methods, origins, and payload sizes are constrained where appropriate. Errors returned to Users are designed to be useful without exposing credentials, private records, or internal exception details.

6

Monitoring and incident response

Security-relevant authentication, billing, and operational activity produces logs or audit records used to investigate unexpected behavior. When we identify a suspected incident, our response is to validate scope, contain access, preserve relevant evidence, correct the underlying issue, and notify affected customers or authorities when required by law.

No internet service can eliminate every risk. We review material reports and improve controls as the service and threat environment evolve.

7

Customer security checklist

  • Enable authenticator-based two-factor authentication.
  • Use a unique, protected email account and review sign-in prompts before approving them.
  • Give each User the least-privileged role needed for their work.
  • Remove departed personnel and obsolete invitations promptly.
  • Keep browsers and devices updated, encrypted, and protected by a screen lock.
  • Do not upload payment-card numbers, authentication secrets, or unrelated sensitive personal information as operational notes or evidence.
  • Report unexpected account, workspace, or billing activity immediately.
8

Responsible vulnerability disclosure

We welcome good-faith reports that help protect LoadOut customers. Email support@loadoutoperations.com with a clear description, the affected surface, reproduction steps, potential impact, and any non-sensitive evidence needed to understand the issue. Please allow reasonable time for investigation and remediation before public disclosure.

When researching or reporting an issue:

  • use only accounts, workspaces, and data that you own or have explicit permission to test;
  • stop if you encounter another person’s data and report the exposure without retaining or sharing it;
  • do not perform denial-of-service testing, social engineering, phishing, physical attacks, spam, or destructive actions;
  • do not modify or delete data, degrade service, establish persistence, or access more information than needed to demonstrate the issue; and
  • do not include passwords, session tokens, authentication codes, payment details, or unnecessary personal information in the report.

This process does not create a bug bounty, promise payment, authorize testing of third-party systems, or waive legal rights. Reports about Cloudflare or Stripe systems should also follow those providers’ disclosure processes.

9

Security questions

Customers evaluating LoadOut may send security and data-handling questions to support@loadoutoperations.com. Please do not request or send production credentials, signing secrets, private architecture details, or another customer’s information.

Questions about this page?

Contact the LoadOut team and include the name of the policy in your message.

support@loadoutoperations.com
Open LoadOut
LoadOut

Warehouse-first operations for event-rental teams.

ProductWorkflowPricingSecuritySign in
LegalTerms of ServicePrivacy PolicyContact
© 2026 LoadOut OperationsThe right equipment. On the right truck. Ready for the next event.