Trust
Security & Trust
This page is maintained by the The Everlasting EV team to answer common security and privacy questions from customers, banks and manufacturer partners. It describes the controls that are enabled today; it is not an independent certification.
Encrypted in transit
All connections to the platform use TLS. Sensitive documents you upload are encrypted end-to-end between your browser and our storage.
Encrypted at rest
Customer data and uploaded documents are stored in access-controlled infrastructure with encryption at rest managed by our cloud provider.
Row-level access
Row-level security policies ensure that customers only see their own data. Partners (banks, manufacturers) only see the applications routed to them.
Certified payments
Reservations and deposits are processed by certified payment providers. We never store full card numbers or bank credentials on our systems.
Role-based access
Admin, bank, manufacturer, insurance and customer roles each have separate permissions. Sensitive actions are audited.
Secure authentication
Sign-in is protected by Supabase-managed auth with support for email/password and Google sign-in. Passwords are hashed, never stored in plain text.
Shared responsibility
We secure the platform; you help protect your account by using a strong, unique password, keeping your email account secure and only sharing information with partners you recognise inside the platform.
Report a vulnerability
If you believe you have found a security issue, please contact us at security@everlastingev.com and give us a reasonable window to investigate and fix before public disclosure.