CertifiedLoads Download PDF
Freight Security Analysis · Edition 1

The Post-Dispatch Gap

The industry verifies carriers thoroughly before a load moves and proves possession after it arrives. Nobody governs the window in between.

Published August 2026  ·  Method Review of publicly available vendor documentation  ·  By Vedran Marjanovic, CertifiedLoads

Every claim in this report is sourced to a vendor's own published material: help pages, terms of service, press releases and product documentation. Nothing here relies on private information, and every finding can be checked against the footnotes.

The finding

13 of 13 publicly document
controls before dispatch.
0 of 13 publish a control
that governs the window after it.

Every platform reviewed publishes checks on operating authority, insurance and safety data before a load is assigned. Most now document identity verification for the account holder. None publishes a control over who can act on a load between the moment it is dispatched and the moment it is collected.

This is not a criticism of any operator. Several say the same thing in their own guidance, directing customers to confirm driver identity independently before releasing freight. They are describing an industry-wide gap honestly, not admitting a fault.

The window opens at dispatch

The pickup is real. It is where the load is actually lost, and every control the industry has built sits there. What the word hides is that the pickup is the end of the problem, not the start of it. By the time a stranger is standing at a gate, every decision that let him get there was already made.

The exposure opens the moment a load is dispatched to a carrier, and it stays open until the freight is in the right hands. Both ends matter. Only one of them is currently owned by anybody.

From that moment forward, a set of questions has no owner. Who else can see this load. Was that carrier's account already compromised last week. Is someone watching this move and planning to arrive before the assigned driver does. Nothing in the current stack answers any of them, because the controls that exist sit on either side of the window rather than inside it.

Vetting happens before. Proof of delivery happens after. The hours or days in between belong to whoever holds the information, and the industry has never defined who that should be.

Communication-based attacks reached 50% of classified freight fraud vectors in the second quarter of 2026. That figure alone relocates the problem. Attacks that begin in an inbox are not attacks on a gate. They are attacks on the window, and they succeed long before anyone arrives to collect anything.

Where protection stops

A load passes through seven distinct stages between order and delivery. The industry has invested heavily on both sides of the fourth and almost nothing inside it.

A
Company vetting
Authority, insurance, safety data
B
Account identity
Who is behind the login
C
Dispatch integrity
Is this carrier assigned
D
Dispatch to pickup
Who can act on the load in between
E
In transit
Tracking
F
Delivery
eBOL, proof of delivery
G
Cross-platform
Loads booked elsewhere

What the industry has built

Where controls do exist, they sit at the far end of the window, at the point of release. Across the thirteen platforms reviewed they fall into four patterns. Each one is checked when somebody arrives, which is after every decision that matters has already been made.

PatternWhat it provesWhat it does not
A per-vehicle code That someone holds a number issued for that load. Anything about who is holding it. Codes travel by email and phone.
A geographic condition That a device reached the pickup area. Who is carrying the device.
A shared phrase or one-time code Possession of a phone number or a message. Whether that number still belongs to the assigned person.
A document plus generic photo ID That a person has identification and a release form. Whether that person appears on any authorised list for that load.

Each of these is a reasonable control and each was a genuine improvement on paper slips. All of them run at the gate. None of them governs the days before it, which is where the load was actually lost.

What a control over the window would have to prove

Naming the gap is straightforward. Specifying the control that closes it is not, and the industry has not agreed on a definition. At minimum it has to hold across the whole window rather than fire once at the end, and it has to separate four things that current controls tend to conflate: possession of a token, presence at a location, the identity of a person, and that person's authorisation for that specific load at that specific moment.

Every published control found in this review addresses one or two of those. None addresses all four.

Why now

Blocked fraudulent inbound emails rose 48.5% in three months. Intercepted spoofed calls rose 159.3% year over year. Impersonation of a single freight brand rose 282% in one quarter.

None of that activity targets the loading dock. It targets the information that reaches the person who shows up, and it succeeds because arriving on time with correct paperwork is still sufficient.

There are a number of handoffs that take place and a lot of different stakeholders involved when moving vehicles. Those handoff points create opportunities for bad actors. Lainey Sibble, head of Central Dispatch, Cox Automotive

Method and limits

This review covers publicly available documentation only: vendor help pages, terms of service, product pages and press releases, read between June and August 2026. It does not cover private roadmaps, unpublished features, contractual controls, or anything a vendor chooses not to document.

An absence in this report means an absence of published evidence. It is not a statement that a capability does not exist. Vendors who have controls we could not find are invited to send them and the next edition will reflect them.

What this report does not cover

This analysis establishes where the gap sits and what a control would need to separate. It does not assess how any individual operation is exposed, which depends on how that business dispatches. That is the subject of a separate assessment.

Who can see your loads right now?

If you want an honest look at what happens to a load between the moment you dispatch it and the moment somebody collects it, get in touch. No charge for the first conversation.

Book a 30-minute walkthrough Or email us

Sources and method

Two categories of source sit behind this analysis.

Industry data. Loss and incident figures are drawn from independent third parties, cited so they can be checked directly.

  1. Highway, Q2 2026 Freight Fraud Index, 28 July 2026
  2. Verisk CargoNet, 2025 theft trends

Platform review. The coverage finding is based on the security material that thirteen auto transport platforms and six general freight platforms publish about themselves: product and security pages, help centre articles, terms of service, and press releases, all reviewed in August 2026.

Individual platforms are not named, and that is deliberate. This is a finding about where the industry as a whole stops, not a scorecard on any one company. Published documentation is also not the same as full capability. A platform may operate a control it has chosen not to describe publicly, so an absence here means an absence of published evidence, nothing more. Anyone who wants to repeat the review can do so from the same public pages.