Security
Last updated: 8 July 2026
Security is built into CarsEXP by design, not added on top. This page summarises the technical and organisational measures that protect your workshop and your customers’ data.
EU hosting & data residency
CarsEXP runs on infrastructure located in the European Union and is operated by an EU legal entity (GBO Eesti OÜ, Estonia). Your data does not leave the EU as part of normal operation.
Strict tenant isolation
Every workshop is a separate tenant. Data is isolated at two levels at once: PostgreSQL Row-Level Security (FORCE RLS, enforced by the database on every query) plus an application-level organisation filter. A request without a valid tenant context is denied by default — one workshop can never read another’s data.
Encryption
All traffic is encrypted in transit with TLS (HTTPS everywhere, automatic certificate renewal). Data at rest is protected by provider-level disk encryption. Passwords are never stored in clear text — only as salted hashes; passkeys use public-key cryptography and never transmit a shared secret.
Strong, passwordless authentication
Sign-in supports passkeys (WebAuthn), national eID (Smart-ID / Mobiil-ID) and one-time codes by e-mail or SMS. Sessions are stored in HTTP-only cookies with server-side expiry; “act as tenant” support access is strictly read-only and time-boxed.
Access control & audit trail
Every action is checked against role-based permissions (RBAC). Significant changes are written to a tamper-evident audit log: records are chained by hash so any modification breaks the chain, and key records are signed (Ed25519) for integrity.
Money & payments integrity
Financial amounts are stored as exact decimals (never floating point), with price snapshots on order and invoice lines. Payments and provider webhooks are idempotent, so a retry can never double-charge or double-post.
Backups & availability
The database is backed up regularly and monitored for health. Services run isolated from unrelated workloads on the same infrastructure.
Privacy & your rights (GDPR)
For customer records a workshop enters, the workshop is the controller and CarsEXP is the processor; a Data Processing Agreement is available. You can export your organisation’s data at any time. See our Privacy Policy for details.
Reporting a vulnerability
If you believe you have found a security issue, please contact security@carsexp.com. We welcome responsible disclosure and will respond promptly.