Trust

Security and compliance

Last updated September 14, 2026. What GoLow does today to protect Host and Guest data, where our SOC 2 Type I work stands, and what we do not claim.

How we protect your data today

Access control per user

Every record is protected by row-level rules. Your account reads only its own data, Hosts reach only their own vehicles and reservations, and administrative views require an admin role stored in a separate, non-editable roles table.

Encryption in transit

The entire site, including checkout and document uploads, is served over HTTPS. Database connections are encrypted, and data at rest sits on encrypted managed storage.

Private documents

Registration, insurance policies, VIN and license plate are never public. Files are served through signed links that expire, so a leaked URL stops working.

No card or bank data on our servers

Card details are collected directly by our PCI-compliant payment provider. Host bank details are entered on the provider's own onboarding flow. GoLow stores only tokens, the last four digits and the result of each charge.

Server-side pricing integrity

Trip totals, protection fees, taxes, Host earnings and refundable holds are recalculated on the server at booking time and locked afterward, so prices cannot be modified from a browser.

Continuous scanning

We run automated security scans against the database policies and the application, and remediate findings before release.

SOC 2 Type I — in preparation

GoLow is preparing for a SOC 2 Type I examination covering the Security trust services criteria. A SOC 2 report can only be issued by an independent licensed CPA firm, so until that examination is complete we describe this work as in progress, not achieved.

  1. 1

    Gap assessment

    In progress

    Map our current controls against the SOC 2 Security criteria and list what is missing.

  2. 2

    Written policies

    In progress

    Formal information security, access, incident response, change management, vendor and risk policies, signed by management.

  3. 3

    Evidence collection

    Planned

    Document access reviews, onboarding and offboarding, backups, logging and vendor due diligence.

  4. 4

    Independent audit

    Planned

    Engage a licensed CPA firm for the SOC 2 Type I point-in-time examination.

What we do not claim

  • GoLow does not hold a completed SOC 2 Type I or Type II report.
  • GoLow is not ISO 27001 certified.
  • GoLow does not hold its own PCI DSS attestation. Card data is handled entirely by our PCI-compliant payment provider, which does.
  • GoLow is not HIPAA regulated, and we do not collect health information.

If a partner asks for a certification we do not yet hold, we will say so directly rather than imply otherwise.

Report a security issue

If you believe you have found a vulnerability, email support.team@golowcar.com with the subject line "Security". Include the steps to reproduce and, if possible, a screenshot. We acknowledge reports within 2 business days and will keep you updated until the issue is resolved. Please do not access other users' data, degrade the service, or disclose the issue publicly before we have fixed it — we will not pursue good-faith researchers who follow this.

Related pages: Privacy Notice, Terms and Conditions, Protection Policy.