Last updated: September 26, 2026
Shops trust AutoSync with customer, vehicle and payment information. These are the safeguards built into the platform.
Account security
- Passwords are hashed with modern algorithms (Argon2id or bcrypt) and never stored in plain text
- Optional two-factor authentication with authenticator apps
- Sign-in rate limiting and temporary lockout after repeated failed attempts
- Server-side sessions that can be reviewed and revoked from your account
Data isolation and access control
- Every organization's data is isolated and every request is checked against the signed-in organization
- Role-based permissions and location-level access for staff
- Audit logs record important actions, including any support access
- Support staff access to a shop account is time-limited, requires a stated reason and is recorded
Application security
- Encrypted connections (HTTPS) for all traffic in production
- Protection against cross-site request forgery on every form
- Secrets and integration credentials encrypted at rest
- Signed, expiring links for customer-facing inspections, approvals and payments
Payments
Card payments through AutoSync Pay are processed by Stripe, a PCI DSS Level 1 certified provider. Card numbers are entered into Stripe-hosted components and are not stored on AutoSync servers.
Responsible disclosure
If you believe you have found a security vulnerability, email support@autosyncshopmanager.com with details. Please give us reasonable time to investigate before disclosure.