How BayNerve Protects Auto Repair Shop and Customer Data

Security and trust 13 min read

BayNerve connects customer details, vehicle records, inspections, estimates, approvals, repair evidence, invoices, and service history. Our responsibility is to keep that information protected, limit how it is used, and be precise about the security controls behind the product.

Gearbox Technologies Gearbox Journal · Opelika, Alabama
BayNerve auto repair shop management software dashboard
The information in a repair record is useful because it is specific. That is also why it has to be protected.
Quick answer

How does BayNerve protect shop and customer data?

BayNerve uses role-based access, separate user accounts, protected production databases, network restrictions, encrypted infrastructure, monitoring, backups, and carefully selected service providers. Just as important, Gearbox Technologies limits data use to operating, supporting, securing, and improving the product. Shop and customer records are not a side product to sell.

Security can become vague very quickly. Software companies list a row of badges, use broad language, and leave the customer to guess what any of it changes during a normal workday.

We want to explain BayNerve differently. An independent repair shop should be able to understand what information the product holds, who can reach it, what the infrastructure protects, and where the shop still has a role to play.

Protecting data is not only about stopping a breach. It is also about stopping the wrong person, process, or product feature from using information in the wrong way.

What BayNerve is responsible for protecting

BayNerve is not a generic contact database. It follows a repair from appointment and check-in through inspection, estimate, customer decision, repair work, invoice, payment record, and vehicle history. That means the product may hold information that matters to the shop, the customer, and the technician who performed the work.

Shop and staff records Shop settings, labor rates, bays, staff accounts, assigned roles, and the work attached to each person.
Customer and vehicle records Contact details, vehicle information, mileage, concerns, visit history, and deferred work.
Repair evidence Inspection findings, measurements, notes, photos, voice notes, parts blockers, and quality checks.
Commercial records Estimates, approved and declined lines, signatures, invoices, payment status, and receivables.

A shop needs this information to do the work and stand behind it later. BayNerve should make the record easier to use without making it easier to misuse.

Our rules for proper data use

Security starts before a firewall or an audit. It starts with deciding what the product is allowed to do with the information entrusted to it.

Use the record to serve the shop

Shop and customer information is used to run the BayNerve service, provide support, secure the system, maintain the record, and improve the product. It is not collected to become an unrelated advertising profile.

Do not sell the repair record

Gearbox Technologies does not treat customer contacts, vehicle histories, inspection photos, estimates, or repair decisions as a data product to sell to brokers or advertisers.

Collect what the workflow needs

A repair record should contain the information needed to inspect, authorize, complete, invoice, and document the work. It should not become a place to store unrelated sensitive details.

Explain changes before they matter

When a new feature changes how information is processed or shared, the right approach is to update the product terms and privacy notice, explain the change, and give shops a clear understanding of what is happening.

One account per person, with access based on the job

A shared shop login may feel convenient, but it removes accountability. It becomes harder to know who approved a change, who closed a work order, or whether a former employee can still enter the system.

BayNerve includes the people in the shop under one shop subscription, so a shop does not have to share credentials to avoid another per-user charge. Owners, service advisors, technicians, administrators, and read-only users can have their own accounts.

Role Access should match the work
Technician Assigned and claimable work, inspections, notes, photos, labor, blockers, and approved repair lines.
Service advisor Appointments, check-in, estimates, approvals, customer communication, invoices, and closeout.
Owner or manager Shop-wide work status, staff access, settings, receivables, reporting, and oversight.
Read-only user The records needed for review, such as closed invoices, without the ability to change the repair workflow.

Permissions are not only a convenience feature. They reduce the number of people who can make a sensitive change and make it easier to remove access when someone leaves the shop.

Behind the application

Production data should not be handled like test data

BayNerve uses managed PostgreSQL infrastructure from Neon. The controls below belong to that infrastructure layer and are part of how we reduce unnecessary exposure around production data.

Protected production branches

A protected database branch cannot be deleted or reset by accident. Credentials generated for child development branches are separated so production credentials are not reused in testing.

IP restrictions

Database access can be limited to approved IP addresses or network ranges. A valid credential alone is not enough when the connection comes from an unapproved location.

Private networking

Private networking can route database traffic through AWS PrivateLink instead of sending it across the open internet.

Encryption

The database platform enforces TLS 1.2 or newer for data in transit and encrypts stored data with AES-256.

Backups and recovery

Encrypted backups, recovery tooling, and infrastructure redundancy help reduce the impact of an operational failure or an incorrect change.

Infrastructure details are documented by Neon at neon.com/security and in the Neon security overview.

Monitoring the system without turning the shop into a surveillance feed

Reliable software needs monitoring. We need to know when a database is under unusual load, when connections fail, when storage changes unexpectedly, or when an error starts affecting more than one shop.

The infrastructure behind BayNerve can export operational metrics and PostgreSQL logs to Datadog or an OpenTelemetry-compatible service. That gives the development team a way to spot failures, investigate patterns, and respond before a small issue becomes a long outage.

Monitoring should have a narrow purpose. The goal is to understand system health and security events, not to casually browse customer repair records. Access to logs and production systems should remain limited to the people who need it for support, reliability, or security work.

Availability note: Neon’s Scale infrastructure includes a 99.95% uptime service-level agreement for covered database workloads. That is an infrastructure commitment, not a claim that every part of BayNerve can never experience an interruption.

The distinction matters. Honest security communication should say which company was audited, which layer has an SLA, and what the product team itself is responsible for.

What the compliance standards actually mean

BayNerve is built on infrastructure that has been reviewed against recognized security and privacy frameworks. Those reviews give us a stronger base, but a badge does not replace secure product decisions, correct permissions, careful development, or responsible support access.

SOC 2 Type I and Type II Neon completed a Type I audit in 2023 and later passed Type II. Neon now reports annual Type II audits, which examine whether security controls operated over a period of time.
SOC 3 A public summary of the SOC review is available without requiring a private report request.
ISO/IEC 27001:2022 This standard addresses the management system used to identify, assess, and control information-security risks.
ISO/IEC 27701:2019 This extends the security management framework with privacy controls for handling personal information.
GDPR The infrastructure provider supports data minimization, lawful processing, data-subject rights, processing agreements, and compliant cross-border transfers.
CCPA and CPRA The infrastructure provider documents its obligations around California privacy rights, transparency, retention, and the sale or sharing of personal data.
An important distinction: These audits and certifications belong to Neon, the managed database provider used by BayNerve. Gearbox Technologies should not describe BayNerve itself as independently SOC 2 or ISO certified unless Gearbox completes those audits under its own name. We would rather state the boundary clearly than borrow a vendor’s badge and blur what it covers.

Neon’s current security and compliance documentation is available through its security page and Trust Center.

Security inside the actual repair workflow

A control matters when it changes what can happen to a real work order. Here are a few practical examples.

The technician sees the approved work

The technician should be able to see the customer decision before starting a line item. They do not need access to every shop setting or staff permission.

The approval stays with the estimate

A signature, timestamp, approved line, and declined line stay attached to the same work order instead of being separated across a text message and a paper folder.

The bookkeeper can review without editing

A read-only role can provide access to closed invoices and payment records without giving the person control over active repairs or staff accounts.

A photo belongs to a job

Inspection photos and voice notes stay attached to the vehicle and work order instead of sitting in a personal camera roll or an unsearchable group text.

A former employee can be removed

Individual accounts make it possible to remove one person’s access without changing a shared password for the entire shop.

The shop still has an important role

No software company can secure a shop account by itself. The strongest infrastructure still depends on how accounts, devices, and records are used each day.

  • Give each person their own account. Do not share one owner login across the shop.
  • Remove access when an employee or contractor no longer needs it.
  • Use the lowest role that still lets a person do the work.
  • Keep phones and computers locked, updated, and controlled by the shop.
  • Do not place unnecessary personal or payment information in open notes.
  • Report a lost device, suspicious login, or unexpected account change quickly.

Security is ongoing work

BayNerve is still being improved, and security work does not end when a feature ships. Permissions have to be reviewed as workflows change. Dependencies need updates. Error messages need to avoid revealing more than they should. Support access needs boundaries. Recovery procedures need testing.

Our standard is not to claim that risk has disappeared. It is to reduce the risk, make access deliberate, monitor the systems that matter, correct weaknesses when we find them, and communicate honestly when a shop needs to know something.

That is part of the broader Gearbox Technologies mission. Vehicle information should help people make better decisions. It should not create a new reason for them to lose control of their records.

BayNerve security questions

Is BayNerve SOC 2 certified?

BayNerve uses Neon for managed PostgreSQL infrastructure. Neon completed SOC 2 Type I and Type II audits and now reports annual Type II audits. Those reports cover Neon, not a separate SOC 2 audit of Gearbox Technologies or BayNerve.

Does BayNerve sell shop or customer data?

No. Gearbox Technologies does not treat customer contacts, vehicle records, inspection evidence, estimates, approvals, or repair history as a product to sell to data brokers or advertisers.

Is BayNerve data encrypted?

The managed database infrastructure used by BayNerve enforces TLS 1.2 or newer for data in transit and encrypts stored data with AES-256. BayNerve also uses application access controls so encryption is not the only protection.

Can every employee see every record?

BayNerve uses roles for owners, service advisors, technicians, administrators, and read-only users. Access should be assigned according to the person’s work rather than giving every account the same controls.

How is production data separated from development work?

Protected database branches help prevent production data from being deleted or reset by accident. Child branches receive separate credentials, and network restrictions can limit which locations are allowed to connect.

How does Gearbox Technologies monitor BayNerve?

Operational metrics and PostgreSQL logs can be exported to Datadog or OpenTelemetry-compatible monitoring services. The purpose is to detect failures, unusual behavior, and performance problems while keeping access to production systems limited.

What should a shop do if it sees suspicious activity?

Remove or restrict the affected account, preserve screenshots or relevant details, and contact Gearbox Technologies at info@gearboxtechnologies.com as soon as possible.

Ask us how BayNerve handles your shop’s records

Review the product, see how roles and repair records work, or send the team a security question before moving your shop into the system.

Published by Gearbox Technologies LLC in Opelika, Alabama. Security and product details reflect the BayNerve architecture and provider documentation reviewed on August 3, 2026. Controls, vendors, and product features may change as development continues.

Leave a comment