Security & trust
Last updated 3 September 2026
ChauffeurPilot handles booking, fleet, and payment-adjacent workflows for chauffeured operators. This page summarises how we approach security — it is not a substitute for a customer security questionnaire or DPA.
Principles
- Least privilege for staff and service accounts.
- Encryption in transit (TLS) for public product hosts.
- Tenant isolation so one operator cannot read another’s data.
- Payment card data handled via PCI-conscious Stripe patterns — we do not store raw card numbers on our servers.
Product hosts
- Operator console: app.chauffeurpilot.com
- Public booking embeds: embed.chauffeurpilot.com
- Help centre: help.chauffeurpilot.com
Operational practices
- Access to production systems is limited to authorised Neurodek personnel.
- Dependency and infrastructure updates are applied as part of normal release hygiene.
- Security-relevant incidents affecting customer data are handled with customer notification as required by agreement and law.
Report a vulnerability
If you believe you have found a security issue, email hello@chauffeurpilot.com with “Security” in the subject. Please avoid testing that degrades availability for other customers.
Further documents
See also our Privacy policy and Terms of service. Enterprise buyers who need a formal questionnaire or DPA should contact sales.