VMOTEK

Security

Security, privacy and access control

The answers your IT and finance reviewers will ask for, stated plainly and without claims we cannot evidence.

VMOTEK separates companies, locations, staff roles and fleet customers as distinct access boundaries. Giving a fleet customer visibility never gives them access to your shop operations.

Company and shop boundaries

Data is scoped to the company that owns it, and further scoped by location. A user's role and location assignment determine what they can see and change.

Role-based access

Owner, manager, advisor, technician, parts and finance roles carry distinct permissions. Permissions are granted by role rather than per person, so access stays reviewable.

Two-step verification

Staff can enroll a standards-based authenticator and receive one-time recovery codes. Company policy can require MFA for owners and administrators or for all staff.

Security events and recovery

Enrollment, challenge, recovery-code use, reset and policy changes create accountable events for review. Administrators can reset access without learning a user's authenticator secret.

Portal is a separate boundary

Fleet customer portal access is not a limited staff account. Portal identities live outside the repair application and can only reach their own authorized account data.

Multi-company identity

One email identity can hold authorized memberships with several repair companies. Each membership is granted independently and can be revoked independently.

Data in transit and at rest

Traffic is encrypted in transit, and stored data is encrypted at rest by the managed infrastructure services the platform runs on.

Third-party handling

Card data is handled by Stripe, messaging by Twilio, email by the connected Gmail account. We store references and status rather than duplicating sensitive credentials.

Auditability

Approvals, transfers, receipts, invoices and permission changes are recorded with the acting user and timestamp so activity can be reconstructed.

Availability and backup

The service runs on managed infrastructure with routine backups. Recovery objectives are documented in the customer agreement rather than asserted in marketing copy.

Shared responsibility

Controls work when the customer configures them deliberately

VMOTEK provides company, shop, role and portal boundaries. Each customer remains responsible for deciding who should have access, assigning the correct location and role, removing departed users and protecting connected provider accounts.

Identity

Use individual accounts, protect sign-in credentials and review Google or password-based identities.

Authorization

Grant the least role and location access needed, especially for approvals, finance and purchasing.

Connected services

Protect Stripe, Gmail, Twilio and QuickBooks administrator access and revoke connections no longer used.

Operational review

Review membership, failed delivery, approval activity and unusual business records on a routine schedule.

Data use

Google Workspace Limited Use

VMOTEK uses Google Workspace API data only to provide user-visible email features, including sending shop messages and importing relevant customer replies. Raw or derived Google Workspace data is not used to create, train or improve generalized or non-personalized AI or machine-learning models. This use adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Questions or incidents

Contact and response

Report a suspected security or privacy issue through the VMOTEK contact channel with the affected company, approximate time, observed behavior and a safe way to reach you. Do not include passwords, card numbers or sensitive credentials. We will acknowledge the report, assess scope and communicate next steps based on the facts available and the applicable customer agreement.

FAQs

Security questions we get asked

Ready to move forward?

Send us your security questionnaire

We would rather answer your review process directly than publish claims that do not survive scrutiny.