BrightmotiveBrightmotive
  • Contact
Book a demo
Brightmotive
ISO 27001GDPR
LinkedIn
Product
  • The right part
  • Delivery times
  • Supplier network
  • Fast and simple
  • RMI
  • Order history
  • Bright AI
  • More features
Resources
  • Customers
  • Pricing
  • Integrations
  • Become a partner
  • Security
Company
  • Contact
  • Support
  • Book a demo
  • Careers
  • Terms and conditions
© 2026 Brightmotive
Maliesingel 403581BK UtrechtNetherlands+31 30 22 700 25
Security

How we handle your data

You're trusting us with your customer data, your pricing and your product data. We don't take that lightly.

ISO 27001GDPR

Compliance and hosting

You shouldn't have to take our word for any of this. An external auditor periodically checks how we work, and your data sits in Frankfurt.

ISO 27001 certified

An independent auditor reviews how we build software and run day-to-day operations. Each review comes back with things to improve, which is what the standard is for.

Hosted in Europe

Data is stored and processed in AWS data centres in Frankfurt, Germany. When someone asks where their data lives, you have a one-word answer: Frankfurt.

Accredited data centres

AWS is SOC 2 Type 2 accredited and ISO 27001 certified, so the infrastructure under you carries its own audit trail for a GDPR question.

Your own database

Your data sits in a dedicated database, not pooled with everyone else's. Another customer importing a massive catalogue cannot slow you down.

Backups and recovery

Automated daily backups, restored per customer. If something goes wrong with your data, we fix it without touching anyone else's.

Redundant infrastructure

We run on AWS with redundancy across availability zones and around-the-clock monitoring. Only the people who need access to production have it.

99.99% uptime

Our track record since 2018. Your customers can rely on the catalogue being there when they need it, even during peak hours.

Access and identity

The risk to your pricing usually isn't a hacker. It's a login that ended up somewhere it shouldn't, or an integration nobody checked.

Role-based permissions

You control exactly who can see and do what: who edits pricing, who views order history, who reaches only specific parts of the catalogue.

Device confirmation

Roles that see sensitive data confirm new devices with a six-digit code sent to their mailbox, so a password on its own doesn't get anyone in.

Shared logins

A password that circulates outside the workshop costs you more the further it travels. You can see what the account has been doing and force a fresh one.

A login per mechanic

Log a user out everywhere at once. Because each mechanic has their own login, you act on one person without disturbing their colleagues.

ERP connections

Your ERP is the most sensitive system we connect to. It runs over HTTPS, authenticated with strong, randomly generated Basic Auth credentials or OAuth 2.0.

Third-party apps

Apps reach the Brightmotive API through OAuth, so a user grants limited access without ever handing over a password. Tokens can be revoked at any time.

A history per line item

Every order records who added each line, who changed the quantity, who linked a vehicle and who applied a special discount. It's on the order confirmation page.

Protecting your data

Your net prices are the most valuable thing you put online. Everything here exists to keep them from walking out the door.

Encrypted in transit

Connections are encrypted with TLS: your customers' browsers, the platform and the link to your own systems. Anyone in between sees nothing they can use.

Encrypted at rest

Everything we store is encrypted with AES-256, so your customer data never sits in the open on disk. Passwords are hashed with Argon2id.

Rate limits

A competitor's bot harvesting your net prices at night is a real risk. Every login has a request limit that a scraper hits quickly and a real user never notices.

Traffic reviews

We review every storefront's traffic at regular intervals for the patterns scripted browsing leaves behind, and we act on what turns up.

Peer-reviewed code

All code is reviewed before it reaches production. No change goes live on the strength of one opinion.

Security testing

We run regular security tests against the platform, so vulnerabilities turn up in a report rather than in the wild.

Monitoring

We're usually on a problem before it reaches you. Sometimes our monitoring catches a fault on a partner's side before they do.

More than 40,000 workshops order through wholesalers who trust us with their data

LKQAutodistributionAlliance Automotive GroupNexus NederlandDrive360General Traffic

Questions about security?

We're happy to walk you through our security practices, share our ISO 27001 certificate or answer any questions your team has.

Get in touchBook a demo