Security & data protection
How AutoHound Protects Your Data
AutoHound protects the customer, vehicle, claim, photo, payment, and message data collision shops rely on every day.
Last updated August 15, 2026
Hosting and infrastructure
AutoHound’s primary application, database, and file storage are hosted in US regions. Cloudflare helps protect and route traffic between users and AutoHound.
Encryption
Connections between your browser or device and AutoHound are encrypted in transit using HTTPS and TLS. Databases and object storage are encrypted at rest by our infrastructure providers.
Integration credentials, including QuickBooks Online credentials, are stored encrypted. Customer and adjuster secure-link tokens are stored as one-way hashes rather than readable links.
Shop data isolation
Every shop’s data is separated at the database layer using Row-Level Security policies. These policies restrict each request to the authorized shop.
Automated isolation tests run with every code change to verify that one shop cannot retrieve another shop’s records.
Access controls for your team
Role-based permissions govern what Owners, Admins, Advisors, and Technicians can access. Financial data is excluded for technicians and other roles at the server and query layer. It never reaches their screens, search results, or timelines.
Passwords are securely hashed. Sessions use short-lived, rotating tokens with reuse detection and account lockout. Time-based one-time password two-factor authentication is available.
AutoHound employee and support access
AutoHound employees receive only the production access needed to operate and support the service. Support access can include signing in as one of a shop's users in order to reproduce a problem that shop has reported, and the start of every such session is recorded in the shop's activity log. Administrative and support actions involving customer data are recorded in audit logs.
Backups and recovery testing
The production database is backed up daily with point-in-time recovery snapshots. Daily full backups are retained offsite for 30 days.
AutoHound conducts quarterly recovery exercises by restoring a backup into an isolated environment, running integrity tests, and recording the recovery time.
Incident response and notification
We continuously monitor application and database health and alert our team to outages and suspected problems.
If we determine that a security incident has affected shop data, we will notify affected shops without unreasonable delay and in accordance with applicable law. Reports of suspected security issues can be sent to security@autohound.io.
Your data, exports, and deletion
Your data belongs to your shop. Shop owners can export their organization’s available records in JSON format at any time.
After an account is closed, shop data is removed from active systems within 90 days, subject to applicable legal obligations. Copies remaining in encrypted backups are deleted as those backups expire, within 30 days after that.
Requests concerning an individual customer’s data should normally be directed to the repair shop that collected it. AutoHound will assist shops with appropriate review, correction, export, or deletion requests. See our Privacy Policy for more information.