Skip to main content

Security & Trust

Effective date: September 4, 2026
Last updated September 4, 2026

HQDIRECTOR CORP designs and operates security measures for HQDirector.com, MyHQDirector, and Director applications. Security practices evolve with the services and risks they address; this page is not a certification, guarantee, or claim of absolute protection.

Service boundaries

HQDirector.com is our public storefront, including pricing, news, the Policy Center, and contact workflow. MyHQDirector is the account, organization, subscription, entitlement, and application-launch surface. Director applications, including CrewDirector, AssetDirector, and FleetDirector, are the product surfaces where customers manage their operational work.

Security approach

Our measures are intended to support appropriate access control, authentication, separation of customer organizations, secure delivery, investigation, and response. Controls may include validation, authorization checks, logging, configuration management, and protections against abuse. Their operation can depend on the applicable service, configuration, and provider.

Providers and service dependencies

Replit provides infrastructure used for applicable services. Clerk supports identity and session functions in MyHQDirector. Stripe is the intended payment processor, including Stripe Billing and Stripe Tax. Cloudflare may provide applicable security and delivery functions, and Upstash Redis may hold applicable abuse and security state. When the contact workflow accepts messages, Resend transmits them to the designated Microsoft 365 mailbox and sends a controlled acknowledgment to the submitter. The public experience may also use CSS and system font dependencies.

These dependencies have their own operating boundaries. Their use does not mean that a control applies in every circumstance or that a provider has access to every category of information.

Report a concern

To report a potential security issue, use the Security contact form. Do not include passwords, credentials, payment-card details, private keys, active exploit code, or other exploitable secrets in a report. An acknowledgment confirms intake only, not investigation or resolution.

Questions about this policy?

Reach out to the appropriate HQDirector team for assistance.

Report a Security Concern