1. Overview
DealerOS applies layered technical and organisational measures to protect the confidentiality, integrity, and availability of your data. This policy summarises our key controls.
2. Encryption
Data is encrypted in transit using TLS and protected at rest. Sensitive secrets are stored securely and are never exposed to the client application.
3. Authentication & Session Security
Passwords are hashed using a strong, salted algorithm and are never stored in plain text. Sessions are protected with secure, HTTP-only cookies and expiry controls. Multi-factor authentication is supported to add a further layer of protection.
4. Access Control & Tenant Isolation
Access is governed by role-based access control (RBAC), enforced on the server for every request. Each company’s data is logically isolated through multi-tenant scoping, and sensitive actions are recorded in audit logs.
5. Infrastructure & File Storage
The Service runs on reputable cloud infrastructure. Uploaded files are stored in dedicated object storage with scoped, time-limited access rather than in the application database. Systems are continuously monitored for availability and anomalies.
6. Backups & Disaster Recovery
We maintain regular backups and disaster-recovery practices designed to restore the Service and your data in the event of a significant disruption.
7. Incident Response
We maintain an incident-response process to detect, investigate, and remediate security events, and to notify affected customers where required by law.
8. Contact
Security questions can be sent to support@dealeros.com.