Cardinal AI Cardinal AI
  • How It Works
  • For Dealers
  • Pricing
  • Partners
Get Started
How It Works For Dealers Pricing Partners Get Started

Trust & Security

Data Security

Effective date: January 1, 2026  •  Cardinal AI LLC  •  Governed by the laws of the State of Florida

On this page

  1. Security overview
  2. Encryption
  3. Access controls
  4. Data we do not store
  5. Dealer data isolation
  6. Infrastructure and monitoring
  7. SOC 2 alignment roadmap
  8. Vendor management
  9. Incident response
  10. Reporting a security issue

1. Security overview

Cardinal AI LLC builds auction intelligence software for automotive dealerships, and dealership data is at the center of everything we do. This page describes the technical and organizational controls we use to protect that data. It complements our Privacy Policy and Terms of Service.

2. Encryption

  • In transit. All traffic between your browser or mobile device and Cardinal AI is encrypted using TLS 1.2 or higher, with modern cipher suites and HTTPS enforced across all endpoints. Plaintext HTTP requests are redirected to HTTPS.
  • At rest. Databases, object storage, and backups are encrypted at rest using AES-256. Encryption keys are managed by our cloud provider's managed key service, with keys rotated on a regular schedule.
  • Internal traffic. Service-to-service and database connections within our environment are encrypted, and API credentials for third-party data providers are stored in a managed secrets store rather than in application code.

3. Access controls

  • Role-based access. Platform users are granted permissions based on role — for example dealer principal, used car manager, or buyer — so that each user sees only the rooftops and reporting appropriate to their role.
  • Least privilege for personnel. Cardinal AI employees and contractors receive the minimum access required to perform their work. Production access is limited to a small number of engineering personnel, requires multi-factor authentication, and is logged.
  • Authentication. Accounts require unique credentials; multi-factor authentication is available for platform users and required for administrative and production systems.
  • Offboarding. Access is revoked promptly when personnel leave or change roles, and access reviews are performed periodically.

4. Data we do not store

Cardinal AI is designed to minimize sensitive data. We do not store consumer credit reports, credit scores, social security numbers, bank account numbers, or full payment card numbers. Subscription payments are handled by a PCI-DSS compliant payment processor; card data is transmitted directly to that processor and never persists in Cardinal AI systems. Our platform works with vehicle, inventory, market, and dealership operational data — not consumer financing data.

5. Dealer data isolation

Cardinal AI runs a multi-tenant architecture with logical isolation per dealership. Every record is bound to a tenant identifier, and all data access is filtered by tenant at the application and query layer, so one dealership can never see another dealership's inventory, scoring history, gross figures, or buyer performance. Dealer groups can be configured so that rooftop-level data rolls up only to authorized group users. Backups and exports preserve the same tenant boundaries.

6. Infrastructure and monitoring

  • Hosting is provided by major U.S. cloud infrastructure providers operating physically secure, audited data centers.
  • Environments are separated between development, staging, and production; production data is not used for development or testing.
  • Automated encrypted backups are taken on a regular schedule and restoration is periodically tested.
  • Application and infrastructure logs are centralized and monitored, with alerting on anomalous authentication and access patterns.
  • Dependencies are patched on an ongoing basis, and code changes go through review before release.

7. SOC 2 alignment roadmap

Cardinal AI is building toward a SOC 2 Type II examination. Our current program is aligned to the SOC 2 Trust Services Criteria for security, availability, and confidentiality, and includes documented security policies, formal access reviews, change management, vendor review, logging and monitoring, and an incident response plan. We are progressively formalizing evidence collection ahead of an independent audit. Cardinal AI has not yet completed a SOC 2 audit; we will make the report available to customers under NDA once it is issued. Customers with specific compliance requirements can request our current security documentation.

8. Vendor management

We review the security posture of the subprocessors and data providers we rely on — including hosting, email, analytics, and automotive data providers such as Experian AutoCheck, J.D. Power, Black Book, and Carfax. Vendors are contractually limited to using data only to provide services to Cardinal AI, and vendor access is scoped to what each service requires.

9. Incident response

We maintain a documented incident response process covering detection, triage, containment, eradication, recovery, and post-incident review. In the event of a confirmed security incident affecting your data, we will notify affected customers without undue delay, provide the facts known at the time, and follow up with remediation steps and applicable notifications required by law.

10. Reporting a security issue

We welcome reports from customers and independent researchers. Please email us with steps to reproduce, affected URLs or endpoints, and any supporting detail. We ask that you avoid accessing or modifying other customers' data while testing and give us a reasonable opportunity to remediate before public disclosure.

Cardinal AI LLC — Security

Email: [email protected]

Phone: 305-298-3009

We acknowledge security reports within two business days.

← Back to Cardinal AI
Cardinal AI Cardinal AI

AI-powered vehicle scoring and auction intelligence for automotive dealerships. Not by gut. By numbers.

Product

  • How It Works
  • For Dealers
  • Pricing
  • Request Demo

Company

  • About
  • Partners
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Data Security

© 2026 Cardinal AI LLC. All rights reserved. EIN 42-2376837.

305-298-3009  •  [email protected]  •  cardinaltech.ai