Identity
Use individual accounts, protect sign-in credentials and review Google or password-based identities.
Security
The answers your IT and finance reviewers will ask for, stated plainly and without claims we cannot evidence.
VMOTEK separates companies, locations, staff roles and fleet customers as distinct access boundaries. Giving a fleet customer visibility never gives them access to your shop operations.
Data is scoped to the company that owns it, and further scoped by location. A user's role and location assignment determine what they can see and change.
Owner, manager, advisor, technician, parts and finance roles carry distinct permissions. Permissions are granted by role rather than per person, so access stays reviewable.
Staff can enroll a standards-based authenticator and receive one-time recovery codes. Company policy can require MFA for owners and administrators or for all staff.
Enrollment, challenge, recovery-code use, reset and policy changes create accountable events for review. Administrators can reset access without learning a user's authenticator secret.
Fleet customer portal access is not a limited staff account. Portal identities live outside the repair application and can only reach their own authorized account data.
One email identity can hold authorized memberships with several repair companies. Each membership is granted independently and can be revoked independently.
Traffic is encrypted in transit, and stored data is encrypted at rest by the managed infrastructure services the platform runs on.
Card data is handled by Stripe, messaging by Twilio, email by the connected Gmail account. We store references and status rather than duplicating sensitive credentials.
Approvals, transfers, receipts, invoices and permission changes are recorded with the acting user and timestamp so activity can be reconstructed.
The service runs on managed infrastructure with routine backups. Recovery objectives are documented in the customer agreement rather than asserted in marketing copy.
Shared responsibility
VMOTEK provides company, shop, role and portal boundaries. Each customer remains responsible for deciding who should have access, assigning the correct location and role, removing departed users and protecting connected provider accounts.
Use individual accounts, protect sign-in credentials and review Google or password-based identities.
Grant the least role and location access needed, especially for approvals, finance and purchasing.
Protect Stripe, Gmail, Twilio and QuickBooks administrator access and revoke connections no longer used.
Review membership, failed delivery, approval activity and unusual business records on a routine schedule.
Data use
VMOTEK uses Google Workspace API data only to provide user-visible email features, including sending shop messages and importing relevant customer replies. Raw or derived Google Workspace data is not used to create, train or improve generalized or non-personalized AI or machine-learning models. This use adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Questions or incidents
Report a suspected security or privacy issue through the VMOTEK contact channel with the affected company, approximate time, observed behavior and a safe way to reach you. Do not include passwords, card numbers or sensitive credentials. We will acknowledge the report, assess scope and communicate next steps based on the facts available and the applicable customer agreement.
FAQs
Ready to move forward?
We would rather answer your review process directly than publish claims that do not survive scrutiny.