On this page
1. Security overview
Cardinal AI LLC builds auction intelligence software for automotive dealerships, and dealership data is at the center of everything we do. This page describes the technical and organizational controls we use to protect that data. It complements our Privacy Policy and Terms of Service.
2. Encryption
- In transit. All traffic between your browser or mobile device and Cardinal AI is encrypted using TLS 1.2 or higher, with modern cipher suites and HTTPS enforced across all endpoints. Plaintext HTTP requests are redirected to HTTPS.
- At rest. Databases, object storage, and backups are encrypted at rest using AES-256. Encryption keys are managed by our cloud provider's managed key service, with keys rotated on a regular schedule.
- Internal traffic. Service-to-service and database connections within our environment are encrypted, and API credentials for third-party data providers are stored in a managed secrets store rather than in application code.
3. Access controls
- Role-based access. Platform users are granted permissions based on role — for example dealer principal, used car manager, or buyer — so that each user sees only the rooftops and reporting appropriate to their role.
- Least privilege for personnel. Cardinal AI employees and contractors receive the minimum access required to perform their work. Production access is limited to a small number of engineering personnel, requires multi-factor authentication, and is logged.
- Authentication. Accounts require unique credentials; multi-factor authentication is available for platform users and required for administrative and production systems.
- Offboarding. Access is revoked promptly when personnel leave or change roles, and access reviews are performed periodically.
4. Data we do not store
Cardinal AI is designed to minimize sensitive data. We do not store consumer credit reports, credit scores, social security numbers, bank account numbers, or full payment card numbers. Subscription payments are handled by a PCI-DSS compliant payment processor; card data is transmitted directly to that processor and never persists in Cardinal AI systems. Our platform works with vehicle, inventory, market, and dealership operational data — not consumer financing data.
5. Dealer data isolation
Cardinal AI runs a multi-tenant architecture with logical isolation per dealership. Every record is bound to a tenant identifier, and all data access is filtered by tenant at the application and query layer, so one dealership can never see another dealership's inventory, scoring history, gross figures, or buyer performance. Dealer groups can be configured so that rooftop-level data rolls up only to authorized group users. Backups and exports preserve the same tenant boundaries.
6. Infrastructure and monitoring
- Hosting is provided by major U.S. cloud infrastructure providers operating physically secure, audited data centers.
- Environments are separated between development, staging, and production; production data is not used for development or testing.
- Automated encrypted backups are taken on a regular schedule and restoration is periodically tested.
- Application and infrastructure logs are centralized and monitored, with alerting on anomalous authentication and access patterns.
- Dependencies are patched on an ongoing basis, and code changes go through review before release.
7. SOC 2 alignment roadmap
Cardinal AI is building toward a SOC 2 Type II examination. Our current program is aligned to the SOC 2 Trust Services Criteria for security, availability, and confidentiality, and includes documented security policies, formal access reviews, change management, vendor review, logging and monitoring, and an incident response plan. We are progressively formalizing evidence collection ahead of an independent audit. Cardinal AI has not yet completed a SOC 2 audit; we will make the report available to customers under NDA once it is issued. Customers with specific compliance requirements can request our current security documentation.
8. Vendor management
We review the security posture of the subprocessors and data providers we rely on — including hosting, email, analytics, and automotive data providers such as Experian AutoCheck, J.D. Power, Black Book, and Carfax. Vendors are contractually limited to using data only to provide services to Cardinal AI, and vendor access is scoped to what each service requires.
9. Incident response
We maintain a documented incident response process covering detection, triage, containment, eradication, recovery, and post-incident review. In the event of a confirmed security incident affecting your data, we will notify affected customers without undue delay, provide the facts known at the time, and follow up with remediation steps and applicable notifications required by law.
10. Reporting a security issue
We welcome reports from customers and independent researchers. Please email us with steps to reproduce, affected URLs or endpoints, and any supporting detail. We ask that you avoid accessing or modifying other customers' data while testing and give us a reasonable opportunity to remediate before public disclosure.
Cardinal AI LLC — Security
Email: [email protected]
Phone: 305-298-3009
We acknowledge security reports within two business days.