Security How we handle your data

Trust & security

Secure by design

LT4 handles a dealership's money, customer records, and card payments. This page describes how we protect that today, including the parts we are still building out. If you need detail beyond what is here, ask us and we will put it in writing.

Database safeguards

LT4 uses row-level security on covered tables as an additional tenant boundary. Coverage is still being extended across the system.

Least privilege

Role-based access, two-factor sign-in, and audit logging on sensitive actions.

Correct by construction

Balanced books, with locks that stop the same transaction from posting twice.

Isolation

Row-level security controls

LT4 uses Postgres row-level security on covered tables as an additional tenant boundary. We are still extending that coverage across the system, and we will walk you through exactly where it stands today.

Access

Role-based access

Access follows detailed, role-based permissions that each dealership sets up for its own team, so people see what their job needs.

Authentication

Two-factor authentication

Accounts are protected with authenticator-app two-factor and backup codes. Enforcement is configurable per dealership.

Audit

Audit logging

Payment, sign-in, and administrative actions are recorded with who did it, what they did, the record they touched, the time, and the IP address. We are extending that coverage to more of the system.

Card data

Card data, protected

We never store full card numbers or security codes. LT4 keeps only a secure token, the last four digits, and the card brand, so the sensitive part never lives in your dealership's system.

Money path

Money you can trust

Journal posting validates debit and credit totals before completion. Database locks and idempotency checks help prevent duplicate posting on key money-moving actions.

Encryption

Encrypted in transit

Traffic is served over TLS. Payment and integration credentials are encrypted, and sensitive personal fields such as social security number and date of birth are encrypted in the database.

Infrastructure

Managed AWS infrastructure

LT4 runs on managed AWS with Amazon RDS. If you are evaluating us, ask and we will put our current backup and recovery setup in writing for you.

Get in touch

Vetting us, or found something?

If you're evaluating LT4, or you've found a potential vulnerability, you can reach us directly.

hello@plainspan.com