Security

A dealership's data is not ours to be casual with.

Customer records, conversations and credentials all pass through this platform. Here is how they are handled, and what we do not claim.

  • Encrypted in transit and at rest

    Traffic runs over TLS. Data at rest is encrypted by the managed services we run on, and secrets are held in a dedicated store rather than in application config.

  • Access scoped by design

    Every record carries a store, a location and a department. User groups decide read and write, so a rooftop cannot see another rooftop and a department cannot see outside its own.

  • Your credentials stay yours

    Connections use tokens you grant and can revoke. Where a system has no API, the assistant works it on your own network with credentials you control, and you can turn them off the way you would for an employee.

  • Everything is logged

    Every action an assistant takes is recorded with what it touched and what changed. Automated messages are attributed, and sessions in third-party systems are recorded end to end.

  • Autonomy has limits you set

    Jobs start in advisory. Approval thresholds, quiet hours, frequency caps and a kill switch are all per location, and any job can be pulled back to approval instantly.

  • Your data leaves when you do

    Export any collection at any time. Deletion requests are honoured across the platform, and retention is set per collection rather than assumed.

Messaging

Consent is a record, not a checkbox.

Most of what this platform sends is a message to a real customer. That carries obligations, and we treat them as product requirements rather than fine print.

  • Consent recorded at collection

    Where a number was given, what was shown, and when. Kept for the period the carriers require.

  • Opt-out honoured everywhere

    STOP applies across every channel and every app at once, not just the one it was sent to.

  • Sending limits per location

    Quiet hours and frequency caps stop a routine from ever becoming a nuisance.

The full terms are in our Messaging Terms, including how a customer stops messages and how to reach a person about a message they received.

Practices

How we run it day to day.

  • Least-privilege access for our own team, reviewed when roles change
  • Multi-factor authentication required for administrative access
  • Dependencies and infrastructure patched on a regular cycle
  • Separate environments for development and production data
  • Backups taken continuously, with restores tested
  • Subprocessors listed in the Privacy Policy and kept current

What we do not claim

We are not currently SOC 2 or ISO 27001 certified, and we will not imply otherwise on a sales call. If your group requires a formal audit report or a security questionnaire before you can sign, tell us early and we will tell you plainly where we are.

Disclosure

Found something? Tell us.

We read every report and respond to every one. Please give us a reasonable window to fix an issue before disclosing it publicly, and do not access, modify or retain data that is not yours while testing.

Start here

Bring your security questions.

If your IT team has a list, put them on the call. We would rather answer it up front than in a procurement review.