Security & enterprise trust

Every action is logged, with who did it and when.

Public transport is critical infrastructure. Ordova is built around least-privilege roles, human accountability for consequential decisions, and a complete audit trail.

Built into the platform

Security controls in Ordova today.

Role-based access, enforced server-side

Permissions are checked by the API, not just hidden in the interface. Users can hold multiple roles; effective access is the union of their roles.

Scoped by action and depot

Separate permissions for viewing live operations, approving tactical, strategic or depot-level dispatch, safety holds, finance reports and system configuration.

Audit trail on every action

Authentication events and administrative changes are logged with before/after state; approvals, rejections and modifications are recorded with reason codes.

Hardened authentication

Token-based sessions with refresh-token rotation and reuse detection, rate limiting on sign-in and token refresh, and a production guard against weak signing secrets.

Safe automation

Auto-execution is limited to low-risk, reversible actions and is blocked when a dependent data feed is stale.

Resilient integration

Idempotency keys, retry with exponential backoff and reconciliation queues for failed syncs.

Roles & permissions

Who can do what, by role.

A typical permission model. Roles are configurable; this is the starting point for an authority-scale operation.

Reference role permission matrix
RoleView live opsApprove dispatchEdit schedulesApprove maintenanceFinancial reportsSystem config
Dispatcher YesTacticalNo accessNo accessNo accessNo access
Fleet Manager YesNo accessNo accessAdvisoryViewNo access
Depot Manager Own depotOwn depotNo accessNo accessNo accessNo access
Scheduling Manager YesNo accessYesNo accessViewNo access
Operations Manager AllStrategic / escalatedApproveNo accessViewNo access
Maintenance Manager Maintenance viewNo accessNo accessYesNo accessNo access
Driver Supervisor Driver viewDriver reassignmentNo accessNo accessNo accessNo access
Finance Manager No accessNo accessNo accessNo accessFullNo access
Safety Manager YesSafety holdsNo accessNo accessViewNo access
Authority Executive DashboardNo accessNo accessNo accessFullNo access
System Administrator No accessNo accessNo accessNo accessNo accessFull
Ordova Role Management editor showing permissions grouped by module for the Depot Manager role.
Role Management: permissions grouped by module Real Ordova screen · demo data

Your requirements

Talk to us about your enterprise security requirements.

Hosting model, data residency, encryption, identity integration, penetration testing, certifications and support SLAs are agreed per engagement. We will answer your security questionnaire in detail.

Start a security conversation

Discussed during evaluation

  • On-premises or government-cloud deployment
  • Encryption at rest and in transit
  • Single sign-on / identity provider integration
  • 24×7 support for live-operations modules
  • Data retention and export
  • Security certifications and attestations: none are claimed on this site

Next step

Book a demo with our team.

We’ll walk you through Ordova using your routes, fleet size and current systems.