Security at Dealerloop.
Dealerloop handles dealer business data and customer contact details, so security is table stakes, not a feature. Here's exactly what protects that data today, and an honest view of where our compliance roadmap is.
The controls running right now.
Australian data residency
Production database and backups are hosted in AWS Sydney (ap-southeast-2). Australian customer data is stored in Australia.
Encryption everywhere
All traffic over HTTPS/TLS; database storage and backups encrypted at rest (AES-256). Secrets live in a managed vault, never in code or clients.
Tenant isolation at the database
Every dealership's data is isolated with PostgreSQL Row-Level Security. Cross-tenant access is denied by default at the database, not just the application.
Access control & MFA
Role-based access with least privilege. Multi-factor authentication is enforced on the platform-administration console, with leaked-password protection on all accounts. Dealer staff can review their active session and sign out every other device in one click.
Tamper-evident audit logging
Administrative actions write to an append-only audit log: actor, action, target and timestamp, with immutability enforced by the database. Dealers see their own change history too: every settings change records who changed what, and when.
Controlled change management
Every change ships through version control with pull-request review; production branches are protected against direct pushes and deletion.
Your customers' messages train no one.
Customer messages are processed by Dealerloop's AI to generate replies, and they are never used to train AI models: our agreements with our AI infrastructure providers exclude it. Lead data is used solely to engage and qualify that dealer's enquiries, on the dealer's behalf, and a dealer's data can be exported in full or permanently deleted on request.
Where we are, stated plainly.
Dealerloop is an early-stage company and does not yet hold a SOC 2 or ISO 27001 certification. We run on SOC 2 Type II infrastructure (Supabase and Vercel), the core technical controls those frameworks require are in place today, the list above, and we are committed to pursuing SOC 2, Type I then Type II, with ISO 27001 to follow if our partners require it.
We handle personal information consistent with the Australian Privacy Principles (our privacy policy is published), and messaging compliance is built into the product itself: Spam Act consent, one-tap STOP, quiet hours, AI disclosure.
Running a vendor security review? We'll complete your questionnaire and share our detailed control mapping and SOC 2 roadmap.
Questions about security?
Book a demo and bring your IT lead, or email us and we'll answer in writing.