Comparison Overview

Sapp Bros., Inc.

VS

XPO

Sapp Bros., Inc.

9915 SOUTH 148TH STREET, OMAHA, 68138, US
Last Update: 2026-01-23
Between 650 and 699

Sapp Bros., Inc. is a collection of 18 full-service, friendly travel centers; primarily located on Interstate-80 from as far west as Toquerville, Utah to Clearfield, Pennsylvania in the east. Sapp Bros. is also a leading petroleum wholesale distributor with a robust offering related to refined fuels, lubricants, oil, propane, diesel exhaust fluid, compressed natural gas, kerosene, additives, solvents, and many other associated products, services, and equipment. Sapp Bros. partners with nearly all petroleum manufacturers to ensure their travel centers and 30+ wholesale outlets have the most in-demand products and services. A history of steady and sustained growth has allowed Sapp Bros. Petroleum & Sapp Bros. Travel Centers to operate for over 45 years and have made it their primary focus to treat people kindly and fairly. Relationship-based customer service has given Sapp Bros. the opportunity to establish countless long-term friendships with their customers and business partners. Sapp Bros. transports fuel and lubricants through its own modern and diverse truck fleet. The logistically minded SBT, Inc. aids the operations of Sapp Bros. Travel Centers, Sapp Bros. Petroleum, and its customers, which helps keep costs low. Sapp Bros. is excited about the prospects the future has to offer and looks forward to continuing to serve its valued customers and grow new relationships.

NAICS: 484
NAICS Definition: Truck Transportation
Employees: 303
Subsidiaries: 0
12-month incidents
0
Known data breaches
1
Attack type number
1

XPO

Five American Lane, Greenwich, CT, US, 06831
Last Update: 2026-01-17
Between 750 and 799

XPO provides world-class transportation solutions to the most successful companies in the world. We have a high-energy team around the globe focused on being the best in the industry. Given the scope of our business, there are opportunities to do satisfying work in many different fields, and at all levels of experience. If you’re ready to move the world forward, we’d like to invest in you. (NYSE: XPO)

NAICS: 484
NAICS Definition: Truck Transportation
Employees: 37,582
Subsidiaries: 1
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/sapp-bros.-inc..jpeg
Sapp Bros., Inc.
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/xpologistics.jpeg
XPO
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Sapp Bros., Inc.
100%
Compliance Rate
0/4 Standards Verified
XPO
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Truck Transportation Industry Average (This Year)

No incidents recorded for Sapp Bros., Inc. in 2026.

Incidents vs Truck Transportation Industry Average (This Year)

No incidents recorded for XPO in 2026.

Incident History — Sapp Bros., Inc. (X = Date, Y = Severity)

Sapp Bros., Inc. cyber incidents detection timeline including parent company and subsidiaries

Incident History — XPO (X = Date, Y = Severity)

XPO cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/sapp-bros.-inc..jpeg
Sapp Bros., Inc.
Incidents

Date Detected: 8/2025
Type:Breach
Attack Vector: Hacking
Blog: Blog
https://images.rankiteo.com/companyimages/xpologistics.jpeg
XPO
Incidents

No Incident

FAQ

XPO company demonstrates a stronger AI Cybersecurity Score compared to Sapp Bros., Inc. company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Sapp Bros., Inc. company has historically faced a number of disclosed cyber incidents, whereas XPO company has not reported any.

In the current year, XPO company and Sapp Bros., Inc. company have not reported any cyber incidents.

Neither XPO company nor Sapp Bros., Inc. company has reported experiencing a ransomware attack publicly.

Sapp Bros., Inc. company has disclosed at least one data breach, while the other XPO company has not reported such incidents publicly.

Neither XPO company nor Sapp Bros., Inc. company has reported experiencing targeted cyberattacks publicly.

Neither Sapp Bros., Inc. company nor XPO company has reported experiencing or disclosing vulnerabilities publicly.

Neither Sapp Bros., Inc. nor XPO holds any compliance certifications.

Neither company holds any compliance certifications.

XPO company has more subsidiaries worldwide compared to Sapp Bros., Inc. company.

XPO company employs more people globally than Sapp Bros., Inc. company, reflecting its scale as a Truck Transportation.

Neither Sapp Bros., Inc. nor XPO holds SOC 2 Type 1 certification.

Neither Sapp Bros., Inc. nor XPO holds SOC 2 Type 2 certification.

Neither Sapp Bros., Inc. nor XPO holds ISO 27001 certification.

Neither Sapp Bros., Inc. nor XPO holds PCI DSS certification.

Neither Sapp Bros., Inc. nor XPO holds HIPAA certification.

Neither Sapp Bros., Inc. nor XPO holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Risk Information
cvss3
Base: 9.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Description

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

Risk Information
cvss3
Base: 9.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description

Azure Entra ID Elevation of Privilege Vulnerability

Risk Information
cvss3
Base: 9.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Description

Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, instances configured with the "ldap" component enabled are vulnerable to LDAP search filter injection techniques via the login endpoint. The 401 error response message can be used to determine whether or not a search was successful, allowing for brute force methods to discover LDAP entries on the server such as user IDs and user attributes. This issue has been fixed in version 0.10.0.

Risk Information
cvss4
Base: 2.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versions 3.7.0 and above allow an authenticated user to execute arbitrary system commands on the host server by injecting shell metacharacters into backup filenames. The BackupManager fails to sanitize the filenames of uploaded backups. The system persists user-uploaded files directly to the host filesystem using the raw originalname provided in the request. This allows an attacker to stage a file containing shell metacharacters (e.g., $(id).tar.gz) at a predictable path, which is later referenced during the restore process. The successful storage of the file is what allows the subsequent restore command to reference and execute it. This issue has been fixed in version 4.7.0.

Risk Information
cvss3
Base: 8.0
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H