Autograph is the private operating system for elite automotive collections. The following is a plain account of how we protect what custodians entrust to us — maintained by the Autograph team and updated as the platform evolves.
App-owned content · Not an independent certification
All traffic between your browser and Autograph is encrypted with HTTPS/TLS. Documents, photographs and dossiers travel over the same secured channel.
Vehicle documents are stored in private, non-public buckets. Each file is gated by a server-issued, time-limited link — there is no public URL.
Every record carries an owner. Database row-level security policies make sure custodians can only read and write their own collection, dossiers and drafts.
Administrative consoles (audit, integrations, member invites) are gated by a dedicated super-admin role and re-verified on every server request.
Privileged actions and access attempts — successful or refused — are written to an immutable audit log with timestamp, actor, route and result.
Sensitive operations run inside server functions that re-validate the caller's session and role before touching data. The client cannot bypass them.
Operational practices
Controls that are switched on right now in the live platform, not aspirations.
Data handling
Vehicle dossiers, photographs, documents, valuations, provenance entries, marketplace listings, RFQs, event RSVPs and the activity required to support them.
We do not collect or store payment-card data. Autograph is not a payment processor.
Member data is stored on Lovable Cloud (managed Postgres + private storage) in a single primary region. Backups are retained on the managed platform's standard schedule.
Only the custodian who owns a record, members the custodian has explicitly shared with, and Autograph operators acting under audit.
We do not list, index or surface member identities or holdings to outside parties. Public listings exist only when a custodian deliberately publishes them.
If we identify a security incident that affects member data, we contact the custodians involved directly and explain what happened, what we did, and what they should do.
Found something? Write to concierge@autograph.global with reproduction steps. We acknowledge within two business days.
Control posture
A precise account of what is live in the platform today, what is being rolled out, and what is on the roadmap. Updated as the platform evolves — not a substitute for third-party attestation.
Live today
In progress
Planned
Autograph does not currently hold SOC 2, ISO 27001 or equivalent third-party attestation. HIPAA does not apply — Autograph does not process protected health information. We will publish formal attestations on this page as they are obtained, and we are happy to walk institutional members through the live control set on request.