Trust
Security and compliance
Last updated September 14, 2026. What GoLow does today to protect Host and Guest data, where our SOC 2 Type I work stands, and what we do not claim.
How we protect your data today
Access control per user
Every record is protected by row-level rules. Your account reads only its own data, Hosts reach only their own vehicles and reservations, and administrative views require an admin role stored in a separate, non-editable roles table.
Encryption in transit
The entire site, including checkout and document uploads, is served over HTTPS. Database connections are encrypted, and data at rest sits on encrypted managed storage.
Private documents
Registration, insurance policies, VIN and license plate are never public. Files are served through signed links that expire, so a leaked URL stops working.
No card or bank data on our servers
Card details are collected directly by our PCI-compliant payment provider. Host bank details are entered on the provider's own onboarding flow. GoLow stores only tokens, the last four digits and the result of each charge.
Server-side pricing integrity
Trip totals, protection fees, taxes, Host earnings and refundable holds are recalculated on the server at booking time and locked afterward, so prices cannot be modified from a browser.
Continuous scanning
We run automated security scans against the database policies and the application, and remediate findings before release.
SOC 2 Type I — in preparation
GoLow is preparing for a SOC 2 Type I examination covering the Security trust services criteria. A SOC 2 report can only be issued by an independent licensed CPA firm, so until that examination is complete we describe this work as in progress, not achieved.
- 1
Gap assessment
In progressMap our current controls against the SOC 2 Security criteria and list what is missing.
- 2
Written policies
In progressFormal information security, access, incident response, change management, vendor and risk policies, signed by management.
- 3
Evidence collection
PlannedDocument access reviews, onboarding and offboarding, backups, logging and vendor due diligence.
- 4
Independent audit
PlannedEngage a licensed CPA firm for the SOC 2 Type I point-in-time examination.
What we do not claim
- GoLow does not hold a completed SOC 2 Type I or Type II report.
- GoLow is not ISO 27001 certified.
- GoLow does not hold its own PCI DSS attestation. Card data is handled entirely by our PCI-compliant payment provider, which does.
- GoLow is not HIPAA regulated, and we do not collect health information.
If a partner asks for a certification we do not yet hold, we will say so directly rather than imply otherwise.
Report a security issue
If you believe you have found a vulnerability, email support.team@golowcar.com with the subject line "Security". Include the steps to reproduce and, if possible, a screenshot. We acknowledge reports within 2 business days and will keep you updated until the issue is resolved. Please do not access other users' data, degrade the service, or disclose the issue publicly before we have fixed it — we will not pursue good-faith researchers who follow this.
Related pages: Privacy Notice, Terms and Conditions, Protection Policy.