At Motorsync Ltd, we prioritize system security, data privacy, and continuous threat monitoring across all MIRA products.
- Bank-Grade Encryption: All data in transit is encrypted using TLS 1.3; sensitive data at rest is protected via AES-256 encryption.
- Multi-Tenant Isolation: Strict tenant boundary enforcement prevents cross-dealership data leakage under company-scoped access tokens.
- Responsible Disclosure: We welcome security reports from ethical researchers under our Safe Harbor guidelines.
This policy details technical security measures enforced by Motorsync Ltd ("we", "us", or "MIRA") and sets out guidelines for reporting vulnerability findings responsibly.
1. Technical Security Architecture
MIRA software systems are engineered following industry security frameworks (ISO 27001 / OWASP Top 10) and subject to regular vulnerability scanning:
- Cloud Infrastructure: Hosted in secure UK data centers with automated failover and 99.9% uptime targets.
- Network Defense: Automated Web Application Firewall (WAF), Distributed Denial-of-Service (DDoS) mitigation, and rate limiting.
- Tenant Boundary Controls: Cryptographic token validation and company-level data isolation for dealership databases.
2. Data Encryption & Protection
Data protection is enforced at every layer of system architecture:
- Encryption in Transit: Mandatory TLS 1.3 transport encryption with HTTP Strict Transport Security (HSTS).
- Encryption at Rest: AES-256 volume and database field encryption for PII, document scans, and customer records.
- Sanitised Logging: Automatic masking of sensitive authentication credentials, passwords, and PII from system audit logs.
3. Access Control & Authentication
Account security is protected via risk-based authentication, FIDO2/WebAuthn passkey support, mandatory password complexity rules, and multi-factor authentication options for dealership staff accounts.
4. Vulnerability Disclosure & Safe Harbor
Safe Harbor Commitment: Motorsync Ltd will not initiate legal action against security researchers who discover and report system vulnerabilities in good faith following these guidelines.
Researchers testing MIRA security must abide by the following rules:
- Do not access, modify, or delete customer or dealership data belonging to real accounts.
- Do not execute Denial-of-Service (DoS) attacks, automated spamming, or social engineering.
- Report findings confidentially to admin@motorsync.co.uk and allow reasonable time for remediation before public disclosure.
5. Incident Response & SLAs
We operate a 24/7 security incident response protocol. Upon receiving a verified vulnerability report, our security operations team acknowledges receipt within 24 hours and issues remediation updates based on severity.
6. Reporting Security Inquiries
Motorsync Ltd Security Desk
Email: admin@motorsync.co.uk
PGP Key / Security Contacts: Available upon request for encrypted communications.