Skip to main content

Security posture

Security claims stay tied to evidence.

The public posture distinguishes product boundaries from runtime facts. A design commitment can define what must be true; only current evidence can show how a deployed control behaves.

Governing boundaries

The data promise is deliberately narrow.

These boundaries define the intended product posture. They do not substitute for deployment-specific assurance.

01

Narrow authorized intake

Only dealer-authorized source fields and purposes belong in the operational path.

02

Two-layer privacy control

Dealer-side cleaning is paired with independent intake screening before storage.

03

Tenant separation

Accepted operational records remain bound to the authorized dealer context.

04

No marketing surveillance

Third-party analytics, fingerprinting, and session recording are outside the public-site posture.

05

Canadian data boundary

Storage and non-LLM processing are governed for Canada; any different inference path requires explicit disclosure.

Deployment evidence

Five controls need current proof.

These statements change as infrastructure changes. They should be verified from the exact environment, date, and scope before a dealer relies on them.

Evidence 01

Identity and access

Current provider settings, roles, tenant scoping, session controls, and enforcement evidence.

Evidence 02

Encryption and keys

Current service configuration, key ownership, rotation, and data-path evidence.

Evidence 03

Backups and recovery

Current backup scope, residency, restoration evidence, retention, and recovery testing.

Evidence 04

Edge and runtime path

Current routing, headers, network boundaries, logs, and any cross-region processing.

Evidence 05

Security testing

Dated test scope, result, remediation state, and limits of reliance.

Claim boundary

What this page does not claim.

The absence of an unsupported claim is part of the security posture.

  • Not 01No blanket statement that the system is certified or independently attested.
  • Not 02No promise of zero risk, zero vulnerabilities, or perfect threat prevention.
  • Not 03No compliance conclusion based only on architecture or policy language.
  • Not 04No live-control claim based on a roadmap, mockup, or undeployed configuration.

Next decision

Inspect what enters the system.

The two-layer data-flow page shows the intended treatment of personal information and authorized operational fields.