Trust & security

How we protect your dealership data.

Last updated: April 30, 2026.

UnifiedGarage handles customer PII, deal financials, and service histories - exactly the kind of data that breaks a dealership's reputation if it leaks. We treat the basics seriously and document them here. If you want to verify any of this on your own, our security disclosure email is at the bottom of this page.

Data encryption

Authentication & access

Tenant isolation

Every row in our database carries a dealershipId. Every query is scoped by it at the service layer. Database-level row-level security (RLS) policies provide a second guard so a code mistake can't cross dealership boundaries silently. We test this with multi-tenant fixtures on every release.

Hosting & infrastructure

Backups & disaster recovery

Logging & monitoring

Patching & vulnerability management

Compliance posture

UnifiedGarage is not yet SOC 2 certified - we're a small team and the audit cost is steep. We're building toward it on the same principles that the audit checks. PIPEDA (Canadian privacy law) compliance is documented in our privacy policy; if your dealership requires GDPR-shaped disclosures we're happy to provide them on request.

Security disclosure

Found a vulnerability? Email security@unifiedgarage.com. We respond within 1 business day, work with you on a fix timeline, and credit responsible disclosure publicly if you want.

Have a more specific question? hello@unifiedgarage.com.