← ShiftPilot AI

Trust Center

This page is maintained by ShiftPilot AI to summarize the controls we've built into the platform. It is not a certification. Dealerships deploying ShiftPilot AI for live consumer finance workflows should complete their own legal, security, and penetration-test reviews.

Data isolation

Each dealership's data is scoped by Row-Level Security in the database. Cross-tenant access is not possible through the app or the API.

Access control

Role-based access covers dealer principals, general managers, sales, finance, service, accounting, and read-only. Platform administration is separated and audited.

Audit logging

Sensitive events — role changes, exports, integration connects, support access, deal and finance updates — are written to an append-only audit log.

AI approval workflow

AI agents propose actions. High-risk actions require a manager to approve before execution. Nothing sensitive happens autonomously.

Export controls

Exports require the correct role, are rate-limited, redacted by default, expiring, and audit logged.

Server-side secrets

AI model calls, lender integrations, and payment/billing calls happen on the server. Frontend never receives provider secrets.

In progress

  • · MFA enrollment UI for platform, dealer principal, and finance manager roles.
  • · Published subprocessor list.
  • · Formal data retention policy and automated purge jobs.
  • · Third-party penetration test before broad live deployment.
  • · Legally reviewed Privacy and Terms.

Security disclosures: security@shiftpilotai.io · General trust questions: trust@shiftpilotai.io