Security described in facts, not adjectives.
A dealership conversation can contain identity, contact, vehicle and finance information. Kestrel keeps that information in the UK, separates it by dealership and limits the agent to the actions the dealer approves.
Kestrel Automotive Intelligence, Scotland, UK
What Kestrel commits to
- UK storage and processing
- Transcripts, recordings, customer details, bookings and reporting data are stored and processed on infrastructure in the United Kingdom.
- Models running in the UK
- The model that understands and answers the customer runs on UK infrastructure. The customer's words are not sent to an overseas model API for a reply.
- Dealership separation
- Each dealership's data is held separately and is used to serve that dealership's conversations, bookings and reporting.
- No shared-model training
- Customer conversations are not used to train a shared model for other dealerships or unrelated customers.
- Bounded actions
- Stock answers come from the live feed and bookings can only use available diary slots. Anything outside the approved brief is handed to a person.
- Contractual detail
- Retention, deletion, access and processing responsibilities are documented in the dealership agreement and data processing terms.
What the website itself enforces
The public site is served over HTTPS with strict transport security, a content security policy, restricted browser permissions, anti-framing controls and content-type protection. These website controls are separate from the product security review supplied for a dealership deployment.
Certification status
Kestrel does not claim SOC 2 or ISO certification on this site. Certifications and independent assurance will be named only when they apply directly to the Kestrel service and can be evidenced during procurement.
What is available during procurement
- Data-flow reviewThe systems involved, the fields read and written, and where each processing step takes place.
- Data processing termsController and processor responsibilities, categories of data, retention and deletion arrangements.
- Integration scopeThe access method and permissions required for the website, stock feed, diary and DMS or CRM.
- Operational safeguardsApproved topics, handover rules, booking boundaries and the process for changing them.
For the deeper explanation, read Sovereign by design.
Security and procurement questions: hello@kestrel-automotive.com