This page is maintained by ShiftPilot AI to summarize the controls we've built into the platform. It is not a certification. Dealerships deploying ShiftPilot AI for live consumer finance workflows should complete their own legal, security, and penetration-test reviews.
Each dealership's data is scoped by Row-Level Security in the database. Cross-tenant access is not possible through the app or the API.
Role-based access covers dealer principals, general managers, sales, finance, service, accounting, and read-only. Platform administration is separated and audited.
Sensitive events — role changes, exports, integration connects, support access, deal and finance updates — are written to an append-only audit log.
AI agents propose actions. High-risk actions require a manager to approve before execution. Nothing sensitive happens autonomously.
Exports require the correct role, are rate-limited, redacted by default, expiring, and audit logged.
AI model calls, lender integrations, and payment/billing calls happen on the server. Frontend never receives provider secrets.
Security disclosures: security@shiftpilotai.io · General trust questions: trust@shiftpilotai.io