Roughly 1 in 3 cars we check comes back with something the advert never mentioned.

Information Security Policy

VehicleIQ is committed to protecting the confidentiality, integrity and availability of the information, systems and services used to provide our UK vehicle-checking and PDF report services.

This Information Security Policy explains the principles and safeguards we use to protect vehicle information, transaction records, customer communications and technical data against unauthorised access, accidental loss, misuse, alteration, disclosure or destruction.

No website, database or online transmission method can be guaranteed to be completely secure. However, VehicleIQ takes reasonable and proportionate technical and organisational measures to reduce information security risks.

1. Purpose of This Policy

The purpose of this policy is to:

  • Protect information processed by VehicleIQ;
  • Reduce the risk of security incidents and data breaches;
  • Maintain the reliability and availability of our vehicle-checking services;
  • Prevent unauthorised access to systems and reports;
  • Protect customer, business and third-party information;
  • Support compliance with applicable UK data protection and security requirements; and
  • Establish a consistent approach to identifying, managing and responding to security risks.

2. Scope

This policy applies to the information, systems and services used by VehicleIQ, including:

  • The VehicleIQ website;
  • Vehicle registration searches;
  • Vehicle report generation;
  • Downloadable PDF reports;
  • Customer support communications;
  • Payment and transaction records received from payment providers;
  • Databases and cloud infrastructure;
  • Administrative accounts and systems;
  • Third-party vehicle data services;
  • Email and communication systems;
  • Security logs and monitoring information; and
  • Devices used to manage or operate the service.

This policy also applies to employees, contractors, developers, administrators and third-party service providers who are given authorised access to VehicleIQ information or systems.

3. Information Security Principles

VehicleIQ follows the principles of confidentiality, integrity and availability.

Confidentiality

Information should only be accessible to authorised people, systems and service providers that require it for a legitimate operational purpose.

Integrity

Information should remain accurate, complete and protected against unauthorised or accidental alteration.

Availability

Systems and information should remain reasonably accessible when required to provide vehicle checks, reports, customer support and related services.

Least privilege

Users and systems should receive only the minimum level of access required to perform their authorised functions.

Security by design

Security and privacy considerations should be included when designing, developing, changing or introducing VehicleIQ systems and services.

Proportionate protection

Security controls should be proportionate to the nature of the information, the likelihood of a security incident and the potential consequences for VehicleIQ, its customers and third parties.

4. Information We Protect

VehicleIQ may protect and manage information including:

  • Vehicle registration numbers;
  • Vehicle specifications and history information;
  • Generated vehicle reports;
  • Report and transaction reference numbers;
  • Payment status and limited billing information;
  • Customer support messages;
  • Email addresses provided through support or ordering processes;
  • IP addresses and technical logs;
  • Browser and device information;
  • Account and authentication information;
  • Business, supplier and contractual information;
  • Application source code and configuration information;
  • API credentials, access tokens and encryption keys; and
  • Security monitoring and incident records.

VehicleIQ does not normally receive or store complete debit or credit card numbers. Payment card information is processed by the relevant payment service provider.

5. Roles and Responsibilities

Responsibility for information security is shared by everyone who has access to VehicleIQ systems or information.

VehicleIQ management is responsible for:

  • Approving appropriate security measures;
  • Assessing significant security risks;
  • Assigning responsibility for security-related activities;
  • Reviewing serious incidents;
  • Ensuring appropriate corrective action is taken; and
  • Reviewing this policy when material changes occur.

Authorised employees, contractors and administrators are responsible for:

  • Following this policy;
  • Protecting passwords and authentication methods;
  • Using information only for authorised purposes;
  • Keeping devices and software secure;
  • Reporting suspected incidents promptly;
  • Avoiding unauthorised copying or disclosure; and
  • Completing any required security awareness activities.

6. Access Control

Access to VehicleIQ systems and information is restricted according to operational need.

Where appropriate, VehicleIQ applies controls including:

  • Unique user accounts;
  • Role-based access permissions;
  • Least-privilege access;
  • Administrative access restrictions;
  • Multi-factor authentication;
  • Secure password requirements;
  • Session controls;
  • Periodic access reviews; and
  • Prompt removal of access when it is no longer required.

Shared administrative accounts should be avoided wherever reasonably possible. Where shared access is technically necessary, its use should be restricted and appropriately controlled.

Authorised users must not disclose passwords, authentication codes, API credentials or access links to unauthorised persons.

7. Password and Authentication Security

Passwords used to access VehicleIQ systems should be strong, unique and not reused across unrelated services.

Passwords and other authentication credentials must not be:

  • Shared through insecure communication channels;
  • Stored in unprotected documents;
  • Hard-coded into publicly accessible source code;
  • Committed to public code repositories; or
  • Disclosed to unauthorised individuals.

Multi-factor authentication should be enabled for sensitive accounts where the relevant service supports it, particularly for hosting, domain, database, payment, email and administrative systems.

Credentials should be changed or revoked where unauthorised access is suspected.

8. Data Encryption and Secure Transmission

VehicleIQ uses or requires appropriate safeguards for information transmitted through its systems.

These safeguards may include:

  • HTTPS encryption for website connections;
  • Secure connections to databases and third-party services;
  • Encryption of sensitive credentials and configuration values;
  • Encryption provided by reputable cloud and hosting platforms;
  • Secure payment-provider connections; and
  • Restrictions on transmitting sensitive information through unsecured channels.

Highly sensitive credentials, including database connection details, API keys and payment-service secrets, should be stored through secure configuration or secret-management methods rather than exposed in website content or client-side code.

9. Website and Application Security

VehicleIQ takes reasonable steps to protect its website and report-generation systems against common security threats.

Security measures may include:

  • Secure development practices;
  • Input validation and output encoding;
  • Protection against unauthorised database queries;
  • Authentication and authorisation checks;
  • Secure session handling;
  • Rate limiting and automated abuse controls;
  • Protection against malicious file uploads;
  • Secure error handling;
  • Dependency and software updates;
  • Security logging;
  • Restricted administrative interfaces; and
  • Testing before material system changes are released.

VehicleIQ does not intentionally expose private database credentials, payment secrets, server credentials or third-party API keys through publicly accessible website code.

10. Software Updates and Vulnerability Management

VehicleIQ aims to keep operating systems, website frameworks, software libraries, plugins, packages and other technical components reasonably up to date.

Security updates should be assessed and installed according to:

  • The severity of the vulnerability;
  • The likelihood of exploitation;
  • The importance of the affected system;
  • The availability of a reliable update; and
  • The potential effect of the update on service availability.

Unsupported or unnecessary software should be replaced, isolated or removed where reasonably practicable.

Suspected vulnerabilities should be investigated and prioritised according to the risk they create.

11. Secure Development and Change Management

Material changes to VehicleIQ systems should be planned, tested and reviewed before being released to the live service where reasonably practicable.

Development and change-management measures may include:

  • Reviewing code before deployment;
  • Testing payment and report-generation workflows;
  • Separating development and production environments where appropriate;
  • Restricting production database access;
  • Protecting environment configuration files;
  • Maintaining version-control records;
  • Testing backup and recovery arrangements;
  • Documenting significant changes; and
  • Maintaining a method to reverse unsuccessful deployments.

Real customer, transaction or report information should not be copied into unsecured testing environments unless necessary and appropriately protected.

12. Database Security

Access to VehicleIQ databases should be restricted to authorised applications, users and service providers.

Where appropriate, database safeguards may include:

  • Authentication and access controls;
  • Encrypted connections;
  • Network or connection restrictions;
  • Separate administrative credentials;
  • Database activity logging;
  • Backup procedures;
  • Secure credential rotation;
  • Protection against unauthorised queries; and
  • Deletion or anonymisation of information that is no longer required.

Direct access to production data should be limited to situations where it is necessary for administration, support, investigation or maintenance.

13. Payment Security

VehicleIQ may use independent payment providers to process purchases.

Complete payment card details should be entered directly into the payment provider’s secure payment environment wherever possible.

VehicleIQ does not intentionally store complete payment card numbers or card security codes in its own website database.

Access to payment dashboards, transaction records and payment configuration should be restricted to authorised persons.

Suspected fraudulent or unauthorised transactions may be reviewed, blocked or reported to the relevant payment provider.

14. Vehicle Data Provider Security

VehicleIQ may connect to third-party vehicle information providers through APIs or other secure technical methods.

Vehicle data access credentials should be protected against public exposure, unauthorised use and misuse.

Requests to vehicle information providers may be logged where necessary to:

  • Generate reports;
  • Investigate technical problems;
  • Resolve customer queries;
  • Prevent misuse;
  • Confirm service usage; and
  • Meet contractual or security obligations.

Third-party vehicle data should only be accessed and used for authorised VehicleIQ purposes and in accordance with relevant contractual restrictions.

15. Logging and Monitoring

VehicleIQ may maintain technical and security logs to operate, protect and troubleshoot its services.

Logs may record information including:

  • Login attempts;
  • Administrative activity;
  • Vehicle report requests;
  • Application errors;
  • Payment status events;
  • API requests and responses;
  • IP addresses;
  • Security alerts; and
  • Changes to important system settings.

Logging should be proportionate and should not collect more information than is reasonably required for operational, legal or security purposes.

Access to security logs should be restricted, and logs should be retained only for an appropriate period.

16. Backups and Recovery

VehicleIQ aims to maintain appropriate backup and recovery arrangements for important systems and information.

Depending on the nature of the system, these arrangements may include:

  • Automated database backups;
  • Application and configuration backups;
  • Protection of backups from unauthorised access;
  • Separation of backup data from live production systems where appropriate;
  • Backup retention limits;
  • Recovery testing; and
  • Procedures for restoring affected services.

Backups are intended to support service recovery. They are not intended to retain information indefinitely or override applicable deletion and retention requirements.

17. Device and Endpoint Security

Devices used to access VehicleIQ administrative systems should be reasonably protected.

Protective measures may include:

  • Device passwords or biometric authentication;
  • Automatic screen locking;
  • Operating system and software updates;
  • Anti-malware protection where appropriate;
  • Disk encryption where supported;
  • Secure Wi-Fi and network connections;
  • Restrictions on unauthorised software;
  • Secure disposal or reset of old devices; and
  • Remote access protections.

Administrative systems should not be accessed through public or untrusted devices unless appropriate safeguards are in place.

18. Email and Communication Security

Email and messaging systems can be targeted by phishing, impersonation and malicious attachments.

Authorised users should:

  • Verify unusual payment or credential requests;
  • Avoid opening suspicious links or attachments;
  • Confirm changes to supplier payment details through a trusted channel;
  • Check recipient details before sending information;
  • Avoid sending passwords or secret keys by ordinary email;
  • Report suspicious communications promptly; and
  • Use official VehicleIQ communication accounts for business purposes.

VehicleIQ will never require customers to provide complete payment card details through ordinary customer-support email.

19. Third-Party Service Providers

VehicleIQ relies on selected third parties for services such as hosting, databases, vehicle information, payments, email delivery, analytics, customer support and technical infrastructure.

Before giving a provider access to sensitive information or systems, VehicleIQ should consider:

  • The nature of the information involved;
  • The provider’s security measures;
  • The provider’s reputation and reliability;
  • Contractual confidentiality and data protection requirements;
  • Access restrictions;
  • Incident-notification arrangements;
  • Data location and international transfers; and
  • The process for ending access when the service relationship finishes.

Third-party access should be limited to the information and systems required to provide the relevant service.

20. Information Classification and Handling

Information should be handled according to its sensitivity and operational importance.

Public information

Information approved for public access, such as published website content, general vehicle information and public policies.

Internal information

Operational information intended for authorised VehicleIQ personnel and service providers.

Confidential information

Information requiring restricted access, such as customer communications, transaction information, contracts, internal reports and administrative records.

Highly restricted information

Information requiring the strongest protection, such as passwords, API keys, payment secrets, encryption keys, database credentials and security investigation records.

Confidential and highly restricted information must not be disclosed publicly or shared with unauthorised persons.

21. Data Minimisation and Retention

VehicleIQ aims to collect and retain only the information reasonably required to:

  • Provide vehicle checks and reports;
  • Process and verify payments;
  • Provide customer support;
  • Maintain security;
  • Investigate errors or misuse;
  • Meet legal and accounting obligations; and
  • Establish, exercise or defend legal claims.

Information should not be retained indefinitely without a legitimate purpose.

When information is no longer required, it should be securely deleted, anonymised or otherwise removed from active use, subject to applicable legal, backup and record-keeping requirements.

22. Secure Disposal

Information and devices must be disposed of in a way that reduces the risk of unauthorised recovery.

Depending on the type of information or equipment, secure disposal may include:

  • Secure deletion of files;
  • Removal of user accounts and access tokens;
  • Revocation of API credentials;
  • Resetting or securely erasing devices;
  • Destroying physical documents containing confidential information; and
  • Confirming that third-party providers delete or return information when required.

23. Information Security Incidents

An information security incident may include:

  • Unauthorised access to an account or database;
  • Loss or theft of a device;
  • Exposure of an API key or password;
  • Malware or ransomware;
  • A phishing attack;
  • An unauthorised change to a report or transaction;
  • Loss, alteration or accidental deletion of information;
  • Disclosure of information to an incorrect recipient;
  • Abnormal system or API activity;
  • A denial-of-service attack; or
  • A security incident affecting a third-party provider.

Suspected incidents must be reported promptly to the person responsible for VehicleIQ security.

24. Incident Response

VehicleIQ’s response to an information security incident may include:

  • Recording the incident;
  • Confirming what happened;
  • Containing the threat;
  • Protecting affected accounts and systems;
  • Changing or revoking exposed credentials;
  • Preserving relevant evidence and logs;
  • Assessing the information and individuals affected;
  • Restoring systems from secure backups;
  • Contacting affected service providers;
  • Informing customers or authorities where required;
  • Documenting decisions and actions; and
  • Implementing measures to prevent recurrence.

Security incidents should be prioritised according to their severity, scope and potential impact.

25. Personal Data Breaches

Where an incident involves personal information, VehicleIQ will assess whether it constitutes a personal data breach and whether it creates a risk to the rights and freedoms of affected individuals.

Where legally required, VehicleIQ will notify the UK Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of a reportable personal data breach.

Where a personal data breach is likely to result in a high risk to an affected individual, VehicleIQ will also notify that individual where required by law.

VehicleIQ will maintain an appropriate internal record of personal data breaches, including incidents that do not meet the threshold for regulatory notification.

26. Business Continuity

VehicleIQ aims to maintain reasonable arrangements for continuing or restoring important services following a technical failure, cyber incident or third-party outage.

Business continuity arrangements may address:

  • Website and server failures;
  • Database unavailability;
  • Vehicle data provider outages;
  • Payment provider outages;
  • Loss of administrative access;
  • Domain or DNS problems;
  • Email service disruption;
  • Malware or ransomware;
  • Accidental deletion; and
  • Loss of key personnel or suppliers.

VehicleIQ does not guarantee uninterrupted service, but will take reasonable steps to investigate disruptions and restore affected services.

27. Security Awareness

Individuals with access to VehicleIQ systems should understand the security responsibilities relevant to their role.

Security awareness may cover:

  • Password and multi-factor authentication security;
  • Phishing and social engineering;
  • Safe use of devices;
  • Handling confidential information;
  • Payment fraud;
  • Incident reporting;
  • Secure development practices; and
  • Privacy and data protection responsibilities.

28. Prohibited Activities

Users, employees, contractors and third parties must not:

  • Access systems or information without authorisation;
  • Share credentials with unauthorised persons;
  • Attempt to bypass access, payment or security controls;
  • Introduce malicious software;
  • Copy or disclose confidential information without permission;
  • Use VehicleIQ systems for unlawful purposes;
  • Disable security logging or monitoring without authority;
  • Attempt to identify or exploit vulnerabilities without written permission;
  • Connect unauthorised software or services to VehicleIQ systems; or
  • Retain VehicleIQ information after access has been withdrawn unless legally required.

Suspected misuse may result in access being suspended or terminated and may be reported to relevant service providers or authorities.

29. Security Reporting

Customers, security researchers and other third parties who believe they have identified a security issue affecting VehicleIQ should contact us at:

Email: support@vehicleiq.info

A security report should include, where possible:

  • A clear description of the issue;
  • The affected page or service;
  • Steps needed to reproduce the issue;
  • The potential impact;
  • Relevant screenshots or technical evidence; and
  • Contact details for follow-up communication.

Security researchers must not:

  • Access or download information belonging to other users;
  • Disrupt the availability of the website;
  • Use denial-of-service testing;
  • Alter or delete information;
  • Use social engineering against VehicleIQ personnel or providers;
  • Demand payment in exchange for withholding disclosure; or
  • Publicly disclose an unresolved vulnerability in a way that creates avoidable risk.

Reporting a vulnerability does not create an entitlement to payment or participation in a reward programme.

30. Policy Compliance

Failure by an authorised employee, contractor or service provider to follow this policy may result in:

  • Removal or restriction of system access;
  • Additional security controls;
  • Contractual action;
  • Termination of the relevant working relationship; or
  • Referral to relevant authorities where unlawful activity is suspected.

31. Policy Review

This policy will be reviewed periodically and when significant changes occur, including:

  • Introduction of a new service or report type;
  • Changes to hosting or database infrastructure;
  • Changes to vehicle data providers;
  • Changes to payment systems;
  • A significant security incident;
  • Identification of a material security risk; or
  • Changes to applicable legal or regulatory requirements.

The latest version will be published with an updated “Last updated” date.

32. Contact VehicleIQ

For information security questions, concerns or vulnerability reports, contact:

VehicleIQ
Email: support@vehicleiq.info
Website: vehicleiq.info