Security & Compliance

How DealerAI Pro protects dealership and customer data, controls access, and keeps the platform resilient.

This page is maintained by DealerAI Pro to answer common security and privacy questions about DealerAI Pro. It describes the controls and practices we have implemented in the application. It is not an independent certification, audit report, or legal agreement. For approved compliance documentation or a Data Processing Addendum, please contact us.

SOC 2

SOC 2 Type II — In progress

DealerAI Pro is working toward a SOC 2 Type II attestation. Controls are being designed, documented, and operated. A final report is not yet available. This status is not a certification or guarantee of security.

Status

In progress

Access controls & data isolation

Tenant isolation

Row Level Security (RLS) is enabled on tenant-facing application tables. Each dealership's data is scoped to its own tenant by default.

Role-based access

Users are assigned organization roles (owner, admin, user). Sensitive operations require the appropriate role within the dealership.

Encrypted transport

Data in transit is protected with TLS. The platform uses modern authentication and short-lived sessions.

Audit logging

Key events such as sign-ins, role changes, and subscription updates are recorded for review by dealership administrators.

Security review schedule

Recent reviews
  • Application security scanJuly 16, 2026
  • Connector security scanJuly 16, 2026
  • Database policy scanJuly 16, 2026
  • Database linter reviewJuly 15, 2026
  • Dependency scanJuly 16, 2026

These dates reflect the most recent automated and manual reviews run against the application. Security scanning is one part of a broader security program; passing scans do not guarantee the absence of vulnerabilities.

Shared responsibility

DealerAI Pro runs on the Lovable Cloud platform, which provides the underlying infrastructure, database hosting, and authentication services. DealerAI Pro is responsible for application-level controls such as role assignments, data access rules, feature permissions, and customer data handling practices. Customers are responsible for managing their users, keeping credentials secure, and using the platform in accordance with applicable laws and regulations.

Questions & reporting

If you have a security question, need a copy of our latest controls summary, or want to report a vulnerability, please email security@dealerai.pro. We review all reports and aim to respond within two business days.