Security & data protection
How AutoHound Protects Your Data
AutoHound protects the customer, vehicle, claim, photo, payment, and message data collision shops rely on every day.
Hosting and infrastructure
AutoHound’s primary application, database, and file storage are hosted in US regions. Cloudflare helps protect and route traffic between users and AutoHound.
Encryption
Connections between your browser or device and AutoHound are encrypted in transit using HTTPS and TLS. Databases and object storage are encrypted at rest by our infrastructure providers.
Integration credentials, including QuickBooks Online credentials, are stored encrypted. Customer and adjuster secure-link tokens are stored as one-way hashes rather than readable links.
Shop data isolation
Every shop’s data is separated at the database layer using Row-Level Security policies. These policies restrict each request to the authorized shop.
Automated isolation tests run with every code change to verify that one shop cannot retrieve another shop’s records.
Access controls for your team
Role-based permissions govern what Owners, Admins, Advisors, and Technicians can access. Financial data is excluded for technicians and other roles at the server and query layer. It never reaches their screens, search results, or timelines.
Passwords are securely hashed. Sessions use short-lived, rotating tokens with reuse detection and account lockout. Time-based one-time password two-factor authentication is available.
AutoHound employee and support access
AutoHound employees receive only the production access needed to operate and support the service. Administrative and support actions involving customer data are recorded in audit logs.
Backups and recovery testing
The production database is backed up daily through automated snapshots. Weekly full backups are retained for four weeks.
AutoHound conducts quarterly recovery exercises by restoring a backup into an isolated environment, running integrity tests, and recording the recovery time.
Incident response and notification
We continuously monitor application and database health and alert our team to outages and suspected problems.
If we determine that a security incident has affected shop data, we will notify affected shops without unreasonable delay and in accordance with applicable law. Reports of suspected security issues can be sent to security@autohound.io.
Your data, exports, and deletion
Your data belongs to your shop. Shop owners can export their organization’s available records in JSON format at any time.
After an account is closed, shop data is removed from active systems, subject to applicable legal obligations. Copies remaining in backups are deleted as those backups expire under our retention schedule.
Requests concerning an individual customer’s data should normally be directed to the repair shop that collected it. AutoHound will assist shops with appropriate review, correction, export, or deletion requests. See our Privacy Policy for more information.
