Security overview
Security and AI oversight.
How Architera protects your customers' data and keeps your dealership in control of the AI.
Last reviewed: 7 September 2026
01Control over AI
The AI works inside limits your dealership sets, and your team sees everything it does.
- Your team turns AI on or off per channel and sets reply approval per agent. Webchat replies send within the safety rails.
- Every AI draft, every guardrail decision and every handover is visible in your workspace.
- A person can take over any conversation at any moment.
- AI messages disclose that they are from an AI, starting with the first message of a conversation. The disclosure cannot be removed.
- A rule-based screen checks every interaction without a model. A model-based review checks every email and WhatsApp draft before it is sent.
- Every AI action is written to an audit log your dealership can read. Records cannot be edited or deleted.
- A named person at Architera signs off every change to data, access or the AI before it ships.
02Your customers' data
Architera processes customer data for one purpose: running the platform for your dealership.
- Collected: contact details, vehicle interest and conversation content.
- Never collected: payment card numbers, bank details, health or biometric data. Payments run through your own provider; card data does not pass through the platform.
- Consent decides who may be contacted, per customer, channel and purpose.
- Your data is never used to train AI models, neither by Architera nor by our model providers, whose contracts prohibit it.
- Conversations reach a model only to do work for your dealership, over encrypted connections.
- On request, customer identities are replaced with placeholders before a model processes a conversation, and restored only inside Architera.
- Export returns everything held about a person; erasure removes it in one operation. At the end of a contract your data is exported to you and then deleted, on request.
03Access and isolation
Access depends on dealership membership and assigned roles.
- Isolation is enforced at the database layer on every query, independent of application code, and tested before every release.
- Access requires membership of the dealership or of a parent organisation with permission.
- Roles and permissions are managed by your dealership.
- Credentials that bypass isolation exist only on the server, held by authorised Architera personnel.
04Operations and incident response
The platform runs on managed infrastructure in the European Union under continuous monitoring and a written incident procedure.
- Inbound WhatsApp and email messages are accepted only with a valid signature.
- Changes to access rules, safety controls, secrets and AI providers require approval before release.
- Monitoring runs around the clock and correlates failed sign-ins, denied access, rejected signatures and unusual export volume.
- High-severity findings alert Architera's security contacts immediately, day or night.
- A written incident procedure defines severity, containment, evidence and notification; customers are notified within the contractual window.
05Service providers
Architera builds on established providers for infrastructure, encryption, AI, messaging and payments. The named list is available to customers under contract.
- Cloud infrastructure
- Managed hosting supports the database, authentication, file storage and application.
- AI providers
- Architera selects models for each task.
- Messaging and email
- Providers connect WhatsApp and email to the dealership’s own accounts.
- Payments
- The dealership uses its own payment provider and remains the merchant of record.
06Security questions
Answers security reviewers ask first. For integrations and rollout, read the FAQ page.
How is our dealership's data protected?
Data is encrypted in transit and at rest, isolated at the database layer and backed up automatically on a fixed schedule. Access follows dealership membership and assigned roles; authorised parent organisations and Architera personnel can also have access. Credentials are held in dedicated secret stores and never in source code.
Who at Architera can access our customer data?
Only authorised Architera personnel have server-side access for support or incident work. Actions on customer data are written to the audit log.
Can the AI contact customers on its own?
Your team controls whether each channel uses AI and whether each agent’s replies need approval. Drafts containing a price, discount or commitment require a person’s review. Outreach requires recorded consent.
Does Architera hold a security certification?
Formal certification is planned; controls are documented on this page, questionnaires are answered in full, and evidence is available under contract.
How do we export or delete our data?
On request, Architera exports the information held about a person or erases it in one operation, with an audit record. At the end of a contract, Architera exports your data to you and then deletes it, on request.
How do we report a security issue?
accounts@architera.ai.