Security
Security, privacy and access control
The answers your IT and finance reviewers will ask for, stated plainly and without claims we cannot evidence.
Vlatrix separates companies, locations, staff roles and fleet customers as distinct access boundaries. Giving a fleet customer visibility never gives them access to your shop operations.
Company and shop boundaries
Data is scoped to the company that owns it, and further scoped by location. A user's role and location assignment determine what they can see and change.
Role-based access
Owner, manager, advisor, technician, parts and finance roles carry distinct permissions. Permissions are granted by role rather than per person, so access stays reviewable.
Portal is a separate boundary
Fleet customer portal access is not a limited staff account. Portal identities live outside the repair application and can only reach their own authorized account data.
Multi-company identity
One email identity can hold authorized memberships with several repair companies. Each membership is granted independently and can be revoked independently.
Data in transit and at rest
Traffic is encrypted in transit, and stored data is encrypted at rest by the managed infrastructure services the platform runs on.
Third-party handling
Card data is handled by Stripe, messaging by Twilio, email by the connected Gmail account. We store references and status rather than duplicating sensitive credentials.
Auditability
Approvals, transfers, receipts, invoices and permission changes are recorded with the acting user and timestamp so activity can be reconstructed.
Availability and backup
The service runs on managed infrastructure with routine backups. Recovery objectives are documented in the customer agreement rather than asserted in marketing copy.
FAQs
Security questions we get asked
Ready to move forward?
Send us your security questionnaire
We would rather answer your review process directly than publish claims that do not survive scrutiny.