Security
A dealership's data is not ours to be casual with.
Customer records, conversations and credentials all pass through this platform. Here is how they are handled, and what we do not claim.
Encrypted in transit and at rest
Traffic runs over TLS. Data at rest is encrypted by the managed services we run on, and secrets are held in a dedicated store rather than in application config.
Access scoped by design
Every record carries a store, a location and a department. User groups decide read and write, so a rooftop cannot see another rooftop and a department cannot see outside its own.
Your credentials stay yours
Connections use tokens you grant and can revoke. Where a system has no API, the assistant works it on your own network with credentials you control, and you can turn them off the way you would for an employee.
Everything is logged
Every action an assistant takes is recorded with what it touched and what changed. Automated messages are attributed, and sessions in third-party systems are recorded end to end.
Autonomy has limits you set
Jobs start in advisory. Approval thresholds, quiet hours, frequency caps and a kill switch are all per location, and any job can be pulled back to approval instantly.
Your data leaves when you do
Export any collection at any time. Deletion requests are honoured across the platform, and retention is set per collection rather than assumed.
Practices
How we run it day to day.
- Least-privilege access for our own team, reviewed when roles change
- Multi-factor authentication required for administrative access
- Dependencies and infrastructure patched on a regular cycle
- Separate environments for development and production data
- Backups taken continuously, with restores tested
- Subprocessors listed in the Privacy Policy and kept current
What we do not claim
We are not currently SOC 2 or ISO 27001 certified, and we will not imply otherwise on a sales call. If your group requires a formal audit report or a security questionnaire before you can sign, tell us early and we will tell you plainly where we are.

Start here
Bring your security questions.
If your IT team has a list, put them on the call. We would rather answer it up front than in a procurement review.