Security and data. The controls running right now, and where we are, stated plainly.
Your customers' messages train no one. Every dealership's data is hosted in Sydney, isolated at the database, encrypted everywhere, and every administrative action is logged. This page says what is in place today and what is not yet, in the same voice.
The controls running right now
Security · 1.0- Australian data residencyProduction database and backups are hosted in AWS Sydney (ap-southeast-2). Australian customer data is stored in Australia.
- Encryption everywhereAll traffic over HTTPS/TLS; database storage and backups encrypted at rest (AES-256). Secrets live in a managed vault, never in code or clients.
- Tenant isolation at the databaseEvery dealership's data is isolated with PostgreSQL Row-Level Security. Cross-tenant access is denied by default at the database, not just the application.
- Access control and MFARole-based access with least privilege. Multi-factor authentication is enforced on the platform-administration console, with leaked-password protection on all accounts. Dealer staff can review their active session and sign out every other device in one click.
- Tamper-evident audit loggingAdministrative actions write to an append-only audit log: actor, action, target and timestamp, with immutability enforced by the database. Dealers see their own change history too: every settings change records who changed what, and when.
- Controlled change managementEvery change ships through version control with pull-request review; production branches are protected against direct pushes and deletion.
Your customers' messages train no one
Security · 2.0Customer messages are processed by Dealerloop's AI to generate replies, and they are never used to train AI models: our agreements with our AI infrastructure providers exclude it. Lead data is used solely to engage and qualify that dealer's enquiries, on the dealer's behalf, and a dealer's data can be exported in full or permanently deleted on request.
- Spam Act consent, one-tap STOP, quiet hours, AI disclosuredefaults in the product
- Full export at any timeyour leads and conversations
- Permanent deletion on requestthe whole tenant
Where we are, stated plainly
Security · 3.0Dealerloop is an early-stage company and does not yet hold a SOC 2 or ISO 27001 certification. We run on SOC 2 Type II infrastructure, the core technical controls those frameworks require are in place today, the list above, and we are committed to pursuing SOC 2, Type I then Type II, with ISO 27001 to follow if our partners require it.
We handle personal information consistent with the Australian Privacy Principles (our privacy policy is published), and messaging compliance is built into the product itself: Spam Act consent, one-tap STOP, quiet hours, AI disclosure.
Running a vendor security review? We will complete your questionnaire and share our detailed control mapping and SOC 2 roadmap.