Security at DealerOS
Protecting your dealership data is our highest priority. Here's how we keep your information safe.
Data Encryption
All data encrypted at rest (AES-256) and in transit (TLS 1.3) across our SOC 2 certified database infrastructure and enterprise edge network.
Access Control
Role-based access control (RBAC) with 414 row-level security policies across 166 database tables. Every query is scoped to the authenticated user’s dealership.
Infrastructure
Hosted on an enterprise edge network (SOC 2 Type II certified) with SOC 2 Type II certified database infrastructure. Auto-scaling, DDoS protection, and 99.9% uptime SLA.
Authentication
Multi-factor authentication support, secure password hashing (bcrypt), session management with automatic expiry, and PKCE-based OAuth flows.
Monitoring
24/7 error monitoring, uptime monitoring with 60-second health checks, and automated alerting for any service degradation.
Data Ownership
Your data belongs to you. We never sell, share, or use dealer data for purposes other than delivering our service. Full data export available on request.
API Security
Public API secured with SHA-256 hashed API keys, per-key rate limiting, and granular permission scoping per dealership.
Compliance Roadmap
SOC 2 Type II certification in progress. GDPR-ready data handling practices. Regular third-party security audits planned.
Patent Protection
Patent Pending — our core technology is protected by a provisional patent filing covering our AI-powered dealership management system.
Report a Security Concern
Found a vulnerability or have a security question? We take every report seriously.
support@dmsos.ai