Security

You can't leak what you never keep.

The auto industry learned the hard way what happens when one system holds every customer's data: it becomes a target worth millions. We built the opposite — a platform designed to hold as little sensitive data as possible, isolate what it does hold, and prove consent for all of it.

Most dealership software is a vault: Social Security numbers, credit applications, contracts, and identities for thousands of stores, all in one place. Vaults get ransomed. Our security model starts from a different question — what if there were almost nothing to steal?

Finance Concepts AI is a coaching and deal-support layer, not a system of record. We deliberately minimize what we collect, mask what passes through, and never store the most sensitive categories at all. What follows is exactly how that works — in plain English, because security claims you can't understand aren't security claims.

Data minimization

What we never store

Not encrypted-and-stored. Not stored-then-deleted. Never stored.

Audio recordings

The Live Coach transcribes in real time and keeps a text transcript only. Raw audio of your customers' voices is never written to disk — ours or anyone else's.

SSNs, card & phone numbers

Number sequences that look like Social Security, card, or phone numbers are automatically masked before a transcript is scored or saved. Managers also have a one-tap PAUSE that fully cuts the microphone during credit applications.

Pre-Qual identity details

Credit pre-qualification never stores a Social Security number or date of birth — they're used for the lookup and discarded. We keep the customer's name, the last four digits of their phone, and the score summary. Nothing more.

Protection by design

How we protect what we do hold

Store-to-store isolation

Every dealership's data — chats, sessions, lookups, and product documents — is walled off from every other dealership, enforced at the database layer itself, not just in the app. One store can never see another's data, even if a bug tried.

Encryption everywhere

All data is encrypted in transit (TLS) and at rest, hosted on enterprise cloud infrastructure — the same AWS-backed platforms used by banks and healthcare companies — with automatic daily backups.

Tamper-proof consent log

Every customer consent — for live coaching and for credit lookups — is recorded with who obtained it and when, in an audit log that nobody can edit or delete. Not managers, not admins, not us. The permissions to alter it simply don't exist.

Keys stay server-side

Credentials for our AI and data providers never reach the browser. Lookups and AI processing run through our servers with short-lived, single-purpose tokens — there's nothing in the manager's browser worth stealing.

AI providers under business terms

The AI services we use process data under commercial API terms — your dealership's documents and conversations are not used to train their public models.

Consent before capture, always

Live listening cannot start until the manager confirms the customer's authorization, and a one-tap decline path keeps the microphone off for that deal. Consent isn't a checkbox in a policy — it's a gate in the software.

Where we're headed — stated plainly

We're not SOC 2 certified yet. That independent audit is on our roadmap, scheduled alongside our first multi-store group deployment. We'd rather tell you that directly than imply otherwise — and we'd rather earn trust the way this page does: by holding less, isolating more, and proving consent for everything. If your dealer group has a security questionnaire, send it over. We'll answer every line honestly.

Security questions or something to report? Email hello@financeconcepts.ai — security reports go to the top of the pile.

Bring us your toughest security question

We built this platform after watching the industry's biggest systems become its biggest targets. Ask us anything on a demo — including the uncomfortable questions.