You're trusting us with your customer data, your pricing and your product data. We don't take that lightly.
You shouldn't have to take our word for any of this. An external auditor periodically checks how we work, and your data sits in Frankfurt.
An independent auditor reviews how we build software and run day-to-day operations. Each review comes back with things to improve, which is what the standard is for.
Data is stored and processed in AWS data centres in Frankfurt, Germany. When someone asks where their data lives, you have a one-word answer: Frankfurt.
AWS is SOC 2 Type 2 accredited and ISO 27001 certified, so the infrastructure under you carries its own audit trail for a GDPR question.
Your data sits in a dedicated database, not pooled with everyone else's. Another customer importing a massive catalogue cannot slow you down.
Automated daily backups, restored per customer. If something goes wrong with your data, we fix it without touching anyone else's.
We run on AWS with redundancy across availability zones and around-the-clock monitoring. Only the people who need access to production have it.
Our track record since 2018. Your customers can rely on the catalogue being there when they need it, even during peak hours.
The risk to your pricing usually isn't a hacker. It's a login that ended up somewhere it shouldn't, or an integration nobody checked.
You control exactly who can see and do what: who edits pricing, who views order history, who reaches only specific parts of the catalogue.
Roles that see sensitive data confirm new devices with a six-digit code sent to their mailbox, so a password on its own doesn't get anyone in.
A password that circulates outside the workshop costs you more the further it travels. You can see what the account has been doing and force a fresh one.
Log a user out everywhere at once. Because each mechanic has their own login, you act on one person without disturbing their colleagues.
Your ERP is the most sensitive system we connect to. It runs over HTTPS, authenticated with strong, randomly generated Basic Auth credentials or OAuth 2.0.
Apps reach the Brightmotive API through OAuth, so a user grants limited access without ever handing over a password. Tokens can be revoked at any time.
Every order records who added each line, who changed the quantity, who linked a vehicle and who applied a special discount. It's on the order confirmation page.
Your net prices are the most valuable thing you put online. Everything here exists to keep them from walking out the door.
Connections are encrypted with TLS: your customers' browsers, the platform and the link to your own systems. Anyone in between sees nothing they can use.
Everything we store is encrypted with AES-256, so your customer data never sits in the open on disk. Passwords are hashed with Argon2id.
A competitor's bot harvesting your net prices at night is a real risk. Every login has a request limit that a scraper hits quickly and a real user never notices.
We review every storefront's traffic at regular intervals for the patterns scripted browsing leaves behind, and we act on what turns up.
All code is reviewed before it reaches production. No change goes live on the strength of one opinion.
We run regular security tests against the platform, so vulnerabilities turn up in a report rather than in the wild.
We're usually on a problem before it reaches you. Sometimes our monitoring catches a fault on a partner's side before they do.

We're happy to walk you through our security practices, share our ISO 27001 certificate or answer any questions your team has.