Rubbleo — Skip hire, sorted.

Security Built Around Clear Boundaries

Rubbleo protects each skip operator's workspace through server-enforced tenant boundaries, role-based permissions, signed sessions, private document storage and controlled backups. Security is treated as an operating responsibility, not a badge or unsupported certification claim.

Last reviewed: 29 August 2026

Each workspace is isolated

Authenticated staff, driver and customer-portal sessions resolve their organisation or permitted relationship on the server. Database queries apply that scope before returning operational records.

A tenant identifier supplied by the browser is never treated as authority on its own. Missing, foreign and unauthorised private-document requests receive bounded responses that do not expose storage keys or cross-tenant record existence.

  • Server-enforced organisation scope
  • Separate staff, driver and portal sessions
  • Relationship checks for private documents
  • No security reliance on hidden navigation

Access follows the job role

Rubbleo separates configuration, office operations, finance, read-only and driver capabilities. The server checks the permission for the requested action even when a screen or button is not visible.

Workspace owners remain responsible for inviting appropriate people, removing access promptly and choosing who may see operational, financial or driver information.

Sessions and credentials are controlled

Staff sessions are signed, expire and are invalidated after security-sensitive account changes. Password credentials use modern salted hashing with compatibility controls for older records and reject unsafe or malformed values.

Verification, invitation and recovery links have limited lifetimes. Expired authentication tokens are removed by a scheduled retention process rather than retained indefinitely.

  • Secure session cookies
  • Signed and expiring sessions
  • Rate-limited authentication flows
  • Revocation after password changes
  • Bounded recovery links

Documents stay private

Driver proof and compliance documents are stored in private Cloudflare R2 buckets. New proof uploads are copied to a secondary private bucket, and downloads require a current authorised relationship before storage is read.

Private binary responses use no-store caching, content-type protection and same-origin controls. Database restore snapshots and document manifests support recovery without turning backups into public assets.

What Rubbleo does not claim

Rubbleo does not claim ISO certification, Cyber Essentials certification, independent penetration-test assurance or a statutory compliance guarantee unless and until that evidence exists and is published accurately.

Operators should assess Rubbleo against their own risk, retention, device, staff-access and regulatory requirements. Security questions can be raised before a trial or subscription decision.

Related Rubbleo capabilities

Read the Privacy Notice · Review UK GDPR responsibilities · Read the platform terms · Explore the Rubbleo platform

Buyer questions

Can one skip company see another company's records?

Rubbleo's server resolves the authenticated organisation and applies tenant scope to workspace queries. Private document access also checks the narrower job, customer or driver relationship.

Are driver locations public?

No. Driver location is available only through authenticated, authorised operational workflows and is not exposed through public storefronts or marketing pages.

Is Rubbleo ISO 27001 certified?

Rubbleo does not currently claim ISO 27001, Cyber Essentials or another independent security certification.

Start free trial · See Rubbleo in action