Skip to main content

Security posture

Security claims stay tied to evidence.

MIQ reduces the data it accepts, separates every dealer's records, keeps marketing surveillance out of the product, and supports environment-specific control statements with dated evidence.

SecurityFive-domain evidence board
Control domainDoctrine boundaryDeployment evidenceClaim state
  1. 01Identity and access

    Required: least privilege and tenant-scoped authority

    Required: dated role grants, denial tests, and access review

    Verify before reliance

  2. 02Encryption and keys

    Required: protected transit and storage paths

    Required: dated configuration records and key-lifecycle checks

    Verify before reliance

  3. 03Backups and recovery

    Required: recoverable and isolated copies

    Required: dated restore exercise, scope, and recovery evidence

    Verify before reliance

  4. 04Edge and runtime path

    Required: restricted ingress and runtime authority

    Required: dated origin checks, route controls, and runtime records

    Verify before reliance

  5. 05Security testing

    Required: repeatable control verification

    Required: dated test scope, result, and remediation review

    Verify before reliance

Evidence ruleNo control claim without current, scope-specific evidence

Governing boundaries

The data promise starts with less exposure.

These product commitments narrow what MIQ accepts, how it is used, where it belongs, and who may review it.

01

Narrow authorized intake

Only dealer-authorized source fields and purposes belong in the operational path.

02

Two-layer privacy control

Where dealer-side cleaning is used, it is paired with mandatory independent intake screening before storage.

03

Tenant separation

Accepted operational records remain bound to the authorized dealer context.

04

No marketing surveillance

Ad-tech analytics, fingerprinting, behavioural tracking, and session recording are outside the public-site posture. Hosting and security providers may still process technical request and security metadata as described in the Privacy Policy.

05

Canadian data boundary

Storage and non-LLM processing are governed for Canada; any different inference path requires explicit disclosure.

Buyer assurance

Ask for the evidence behind the control.

MIQ does not use certification or independent-attestation language without the corresponding report. During commercial or diligence review, each requested control statement is limited to the scope supported by dated evidence. If that evidence is unavailable, MIQ does not make the claim.

Next decision

Inspect what enters the system.

The data-flow page shows how dealer-side cleaning works where used, how every intake is screened before storage, and how authorized operational fields are handled.

MECHANUS IQ

Dealership intelligence

Whole-dealership intelligence and an operating system for Canadian automotive and RV dealerships. Machine learning finds the opportunity, MIQ makes the action happen, and the evidence shows what changed.

  • BC RIA dossier · anchored to enacted text
  • Privacy-minimizing intake
  • Human-review boundary
  • Canadian residency by design
  • Application timestamp context

© 2026 Mechanus IQ · British Columbia, Canada

More gross. Faster cash. Fewer repeat failures.

No ad-tech analytics · No session recording · No behavioural tracking