Security
A practical security overview for Aut贸mos贸 Kft., focused on access control, auditability, tenant isolation, payment boundaries, and incident reporting.
Security overview, not a certification statement
Protected Data Scope
- Customer, billing profile, contact, subscription, invoice, notification, and support related records handled inside the provider space.
- Payment-related events and callback metadata used to verify and reconcile payment state.
- Admin and staff actions that require traceability and operational auditability.
Access Control and Auditability
- Administrative access is role and permission based.
- Provider-side actions can be logged for operational auditability and abuse investigation.
- Support and staff access should be limited to what is necessary for operating and supporting the service.
Provider Isolation
- Provider spaces are intended to operate in separated tenant contexts.
- Provider-specific billing, invoicing, payment, and service configuration are managed within the provider scope.
- Customer self-service actions are tied to the relevant provider relationship and context.
Authentication and Self-Service Security
- Account access relies on provider and platform authentication controls.
- Magic link based self-service access should be treated as sensitive access data and shared only with the intended recipient.
- Users are responsible for protecting their own credentials, inbox access, and devices.
External Payment and Invoicing Dependencies
- Payment handling may be delegated to configured third-party payment providers.
- Invoice issuance may be delegated to configured third-party invoicing providers.
- The provider and Komashi platform depend on external infrastructure and service providers for parts of the security and operational stack.
Incident Reporting
Security issues, suspicious access, or reports about possible vulnerabilities should be sent to the provider as soon as possible using the contact channel below.
- Email
- automoso@automoso.hu
- Phone
- +36 70 320 9075
- Website
- automoso.hu
Best Effort Statement
No online service can guarantee absolute security. The provider and the platform aim to apply reasonable technical and organizational measures appropriate to the service model, risk profile, and available infrastructure.