How the product is being hardened
The prototype is private. Public customer access will remain off until production authentication, tenant isolation and operational controls are verified.
Dealership boundaries
Vehicle records now carry an organisation identifier and server-side record access is constrained to the current prototype organisation. A final independent tenant-isolation review is required before multiple customers share the service.
Files and backups
Receipts and documents use private object storage and are served through controlled application routes. Full exports and optional Google Drive backups support recovery, but restore testing and retention policies remain part of launch work.
Authentication and roles
Owner, manager, staff and accountant roles are modelled. Real invitation sending and customer login are disabled until a supported authentication provider is chosen and enforced on every application and API route.
External connections
Billing, Xero, Google Drive and vehicle lookup credentials must stay server-side, be limited to the minimum permissions and be revocable. No provider key is included in browser code.
Launch gate
Before public launch the service needs a threat review, access-control tests, recovery test, privacy and terms review, support process and incident-response contacts.