Security & enterprise trust
Every action is logged, with who did it and when.
Public transport is critical infrastructure. Ordova is built around least-privilege roles, human accountability for consequential decisions, and a complete audit trail.
Built into the platform
Security controls in Ordova today.
Role-based access, enforced server-side
Permissions are checked by the API, not just hidden in the interface. Users can hold multiple roles; effective access is the union of their roles.
Scoped by action and depot
Separate permissions for viewing live operations, approving tactical, strategic or depot-level dispatch, safety holds, finance reports and system configuration.
Audit trail on every action
Authentication events and administrative changes are logged with before/after state; approvals, rejections and modifications are recorded with reason codes.
Hardened authentication
Token-based sessions with refresh-token rotation and reuse detection, rate limiting on sign-in and token refresh, and a production guard against weak signing secrets.
Safe automation
Auto-execution is limited to low-risk, reversible actions and is blocked when a dependent data feed is stale.
Resilient integration
Idempotency keys, retry with exponential backoff and reconciliation queues for failed syncs.
Roles & permissions
Who can do what, by role.
A typical permission model. Roles are configurable; this is the starting point for an authority-scale operation.
| Role | View live ops | Approve dispatch | Edit schedules | Approve maintenance | Financial reports | System config |
|---|---|---|---|---|---|---|
| Dispatcher | Yes | Tactical | No access | No access | No access | No access |
| Fleet Manager | Yes | No access | No access | Advisory | View | No access |
| Depot Manager | Own depot | Own depot | No access | No access | No access | No access |
| Scheduling Manager | Yes | No access | Yes | No access | View | No access |
| Operations Manager | All | Strategic / escalated | Approve | No access | View | No access |
| Maintenance Manager | Maintenance view | No access | No access | Yes | No access | No access |
| Driver Supervisor | Driver view | Driver reassignment | No access | No access | No access | No access |
| Finance Manager | No access | No access | No access | No access | Full | No access |
| Safety Manager | Yes | Safety holds | No access | No access | View | No access |
| Authority Executive | Dashboard | No access | No access | No access | Full | No access |
| System Administrator | No access | No access | No access | No access | No access | Full |
Your requirements
Talk to us about your enterprise security requirements.
Hosting model, data residency, encryption, identity integration, penetration testing, certifications and support SLAs are agreed per engagement. We will answer your security questionnaire in detail.
Start a security conversationDiscussed during evaluation
- On-premises or government-cloud deployment
- Encryption at rest and in transit
- Single sign-on / identity provider integration
- 24×7 support for live-operations modules
- Data retention and export
- Security certifications and attestations: none are claimed on this site
Next step
Book a demo with our team.
We’ll walk you through Ordova using your routes, fleet size and current systems.