DealerDOH

DealerDOH Security Overview

Last reviewed: August 31, 2026 · Version 1.0 · Describes the DealerDOH v1.1 stack.

What this covers

How DealerDOH protects the dealership operational data and staff account information it processes. Scope of that data — deliberately narrow, with no customer/consumer personal or financial information — is described in the Privacy Policy.

Access and identity

Data in transit and at rest

Application protections

Engineering practice

Backups and continuity

Current beta posture, stated honestly: the production database has a verified manual backup procedure — integrity-checked, hash-verified, and stored off the production host — and backups are not on an automated schedule. At v1.1 the production database moves to a managed PostgreSQL provider (Supabase); on the current plan, provider-managed scheduled database backups are not included, so the beta continues to rely on the documented operator backup procedure with verified off-host copies. The application host's persistent disk additionally has provider-managed daily snapshots (7-day retention). Plan tiers and their backup capabilities are deliberately reassessed before any commercial pilot. There is no uptime SLA during the beta.

Incident response

Failures and anomalies surface through error monitoring and structured, request-correlated logs with a named responsible operator. A documented internal procedure covers triage, scoping, evidence preservation, provider coordination, and case-specific assessment of any notification duties.

What we do not claim

No SOC 2, ISO 27001, HIPAA, PCI DSS, or GLBA certification or attestation; no formal WCAG conformance (see the Accessibility Statement); no uptime, encryption-at-rest, or data-residency guarantees. If a claim is not on this page, DealerDOH is not making it.

Reporting a security concern

Please report suspected vulnerabilities or security concerns to support@dealerdoh.com. Good-faith reports are welcome; we will acknowledge, investigate, and fix verified issues.