This page is maintained by DealerAI Pro to answer common security and privacy questions about DealerAI Pro. It describes the controls and practices we have implemented in the application. It is not an independent certification, audit report, or legal agreement. For approved compliance documentation or a Data Processing Addendum, please contact us.
SOC 2
SOC 2 Type II — In progress
DealerAI Pro is working toward a SOC 2 Type II attestation. Controls are being designed, documented, and operated. A final report is not yet available. This status is not a certification or guarantee of security.
Status
In progress
Access controls & data isolation
Tenant isolation
Row Level Security (RLS) is enabled on tenant-facing application tables. Each dealership's data is scoped to its own tenant by default.
Role-based access
Users are assigned organization roles (owner, admin, user). Sensitive operations require the appropriate role within the dealership.
Encrypted transport
Data in transit is protected with TLS. The platform uses modern authentication and short-lived sessions.
Audit logging
Key events such as sign-ins, role changes, and subscription updates are recorded for review by dealership administrators.
Security review schedule
- Application security scanJuly 16, 2026
- Connector security scanJuly 16, 2026
- Database policy scanJuly 16, 2026
- Database linter reviewJuly 15, 2026
- Dependency scanJuly 16, 2026
These dates reflect the most recent automated and manual reviews run against the application. Security scanning is one part of a broader security program; passing scans do not guarantee the absence of vulnerabilities.
Shared responsibility
DealerAI Pro runs on the Lovable Cloud platform, which provides the underlying infrastructure, database hosting, and authentication services. DealerAI Pro is responsible for application-level controls such as role assignments, data access rules, feature permissions, and customer data handling practices. Customers are responsible for managing their users, keeping credentials secure, and using the platform in accordance with applicable laws and regulations.
Questions & reporting
If you have a security question, need a copy of our latest controls summary, or want to report a vulnerability, please email security@dealerai.pro. We review all reports and aim to respond within two business days.