Rubbleo — Skip hire, sorted.
Security Built Around Clear Boundaries
Rubbleo protects each skip operator's workspace through server-enforced tenant boundaries, role-based permissions, signed sessions, private document storage and controlled backups. Security is treated as an operating responsibility, not a badge or unsupported certification claim.
Last reviewed: 29 August 2026
Each workspace is isolated
Authenticated staff, driver and customer-portal sessions resolve their organisation or permitted relationship on the server. Database queries apply that scope before returning operational records.
A tenant identifier supplied by the browser is never treated as authority on its own. Missing, foreign and unauthorised private-document requests receive bounded responses that do not expose storage keys or cross-tenant record existence.
- Server-enforced organisation scope
- Separate staff, driver and portal sessions
- Relationship checks for private documents
- No security reliance on hidden navigation
Access follows the job role
Rubbleo separates configuration, office operations, finance, read-only and driver capabilities. The server checks the permission for the requested action even when a screen or button is not visible.
Workspace owners remain responsible for inviting appropriate people, removing access promptly and choosing who may see operational, financial or driver information.
Sessions and credentials are controlled
Staff sessions are signed, expire and are invalidated after security-sensitive account changes. Password credentials use modern salted hashing with compatibility controls for older records and reject unsafe or malformed values.
Verification, invitation and recovery links have limited lifetimes. Expired authentication tokens are removed by a scheduled retention process rather than retained indefinitely.
- Secure session cookies
- Signed and expiring sessions
- Rate-limited authentication flows
- Revocation after password changes
- Bounded recovery links
Documents stay private
Driver proof and compliance documents are stored in private Cloudflare R2 buckets. New proof uploads are copied to a secondary private bucket, and downloads require a current authorised relationship before storage is read.
Private binary responses use no-store caching, content-type protection and same-origin controls. Database restore snapshots and document manifests support recovery without turning backups into public assets.
What Rubbleo does not claim
Rubbleo does not claim ISO certification, Cyber Essentials certification, independent penetration-test assurance or a statutory compliance guarantee unless and until that evidence exists and is published accurately.
Operators should assess Rubbleo against their own risk, retention, device, staff-access and regulatory requirements. Security questions can be raised before a trial or subscription decision.
Related Rubbleo capabilities
Read the Privacy Notice · Review UK GDPR responsibilities · Read the platform terms · Explore the Rubbleo platformBuyer questions
Can one skip company see another company's records?
Rubbleo's server resolves the authenticated organisation and applies tenant scope to workspace queries. Private document access also checks the narrower job, customer or driver relationship.
Are driver locations public?
No. Driver location is available only through authenticated, authorised operational workflows and is not exposed through public storefronts or marketing pages.
Is Rubbleo ISO 27001 certified?
Rubbleo does not currently claim ISO 27001, Cyber Essentials or another independent security certification.