Trust center
Security at ProAutoSites
Security is built around tenant isolation, least-privilege access, protected integrations, verifiable activity history, and recoverable operations.
Account protection
Administrative access uses login throttling, secure sessions, device-session revocation, role and permission checks, CSRF protection, and multi-factor authentication. Super Admin accounts are required to enroll in MFA.
Data protection
Traffic is protected with HTTPS. Integration credentials, OAuth tokens, privacy identities, incident details, and other protected configuration are encrypted at rest. Sensitive finance and identity fields are excluded from ordinary forms and audit records.
Tenant and integration safety
Dealer-owned records are scoped by dealership and location. Provider callbacks use state validation, signed webhooks, replay controls, bounded requests, and explicit environment enablement. Demo environments simulate outbound effects.
Audit and compliance
Administrative activity is recorded with sensitive values redacted and linked through a tamper-evident hash chain. Privacy requests, consent events, legal holds, vendor access, and security incidents have dedicated records and controlled workflows.
Availability and recovery
Platform health checks cover the database, storage, scheduled jobs, backups, domains, DNS, HTTPS certificates, billing, and message delivery. Backups include restore testing and off-server evidence controls.
Report a concern
Use the contact form and choose support to report a suspected security issue. Do not include passwords, full payment-card information, Social Security numbers, or other protected data in the message.