Account-scoped records
Authenticated requests are scoped to the signed-in account, with database access policies as the final isolation boundary.
Security and trust
OwnHaul is in open beta. This page explains what is implemented today and what has not yet been independently verified.
Last reviewed September 2026
Authenticated requests are scoped to the signed-in account, with database access policies as the final isolation boundary.
Item photos and documents are stored privately and opened through temporary access links rather than permanent public URLs.
AI Camera is optional. It suggests fields from an image, but you review the result and explicitly confirm before an item is created.
Account Settings provides a deletion workflow covering inventory records, stored files, preferences, profile, and authentication account.
Transparency
OwnHaul does not currently claim an independent security audit, penetration test, SOC 2 report, ISO certification, or bug-bounty program. Provider infrastructure certifications are not presented as OwnHaul certifications.
No internet service can promise absolute security. If independent verification is completed later, this page should identify its scope and date rather than using a generic badge.
Send the affected page, a concise reproduction, and the potential impact to hello@ownhaul.com. Do not include passwords, private keys, or another person's personal data.
For data handling and provider disclosures, read the Privacy Policy.