Security & privacy
Your business data is yours. We protect it with industry-standard security practices.
Business Data Isolation
Each business operates in its own isolated data context. Tenant isolation is enforced at the database level — no business can access another business's records.
Account & Permission Controls
Role-based access control ensures staff and technicians see only what they need. Granular permissions control who can view, create, edit, or delete records.
Payment Provider Separation
Payment processing is handled through Stripe, a PCI-compliant payment provider. We never store or access your full card numbers.
Credential Protection
API keys and integration secrets are stored securely with service-only access. Secrets are never exposed to the frontend or returned in API responses.
Auditability
All significant business actions are recorded in an immutable audit log. You can track who did what and when across your operation.
Data Visibility Controls
Service history is internal-only. Customer portal access is scoped — customers see only their own data. Sensitive fields are masked in responses.
Data Export & Deletion
You can request export or deletion of your business data. Account deletion cascades to all associated records in compliance with privacy regulations.
Responsible Data Handling
We handle your business data responsibly — encryption in transit and at rest, secure authentication, and regular security reviews.
Our commitment
We are committed to maintaining the security and privacy of your business data. Our security practices include encryption, access controls, audit logging, and regular reviews. We do not sell your data to third parties. If you have specific security questions or requirements, please contact our team.
Important note
QIXAuto is continuously improving its security posture. We do not make specific compliance certifications or attestations that have not been formally verified. For the most current information about our security practices, please contact sales.