Infrastructure
AutoKnerd runs on established US cloud providers. The application is hosted on Railway; the marketing website on Vercel; and data and authentication run on Google Cloud / Firebase. We inherit the physical, network, and platform security of these providers, which maintain their own independent security certifications.
Encryption
- In transit: all traffic is served over HTTPS/TLS.
- At rest: customer and account data is encrypted at rest by our cloud data store (Google Cloud/Firebase default encryption).
Authentication & access control
- User authentication is handled by Firebase Authentication; sessions are verified server-side on every request, with token-revocation checking.
- Role-based access control (owner, general manager, manager, and team member, plus internal admin) limits what each user can do.
- Multi-tenant isolation: each dealership's data is logically separated and scoped by dealership; access is restricted to the dealership that owns the data.
- Server APIs enforce authorization in code, and the underlying data store uses default-deny access rules.
- Administrative access to production is limited to authorized personnel on a least-privilege basis. [Confirm/expand internal access practices.]
Data handling
- Location: data is processed and stored in the United States.
- Minimization: we collect the data needed to run coaching and reporting, and do not intentionally collect sensitive categories of data.
- Retention: data is retained for as long as needed to provide the Service and on the dealership's instructions; deletion is available on request, and self-service deletion tooling is being added. [Target: a clearly enforced retention window — being implemented.]
- No sale, no ad-targeting, no third-party model training of customer data. The application uses no third-party advertising trackers; the marketing website uses Google Tag Manager for analytics.
- Sub-processors: a current list is published (Google Cloud/Firebase, Railway, Vercel, and Google Gemini for AI). See Sub-processors.
Secure development
Access controls and data flows are reviewed as part of development, and security review is an ongoing practice.
Incident response
We log and review platform activity and will notify affected customers of a confirmed security incident affecting their data without undue delay after confirmation [set an outside window — e.g., 72 hours — only if operationally achievable], consistent with our Data Processing Agreement. [A formal, always-on monitoring/alerting and incident-response program is on the roadmap.]
Compliance posture
US state privacy laws (e.g., CCPA/CPRA): we honor applicable consumer rights (access, deletion, correction) via privacy@autoknerd.com.
Roadmap (not yet in place — not represented as current)
- Automated data-retention/deletion enforcement (in progress)
- Independent third-party penetration test
- SOC 2 Type II examination
- Formal, documented information-security program and vendor-risk process
Contact
Security questions: security@autoknerd.com · AutoKnerd LLC