Trust

Security

How we protect the website, your information and your transactions, and how to report a security issue.

Effective October 5, 2026 · Last updated October 5, 2026

Our approach

We keep our exposure small. The website is a static site with no logins, no customer accounts and no payment pages, so there is very little to attack and very little stored. Information you send us goes only to the people at Silvara who need it to do the work.

The website

  • Encrypted connections. The site and its forms are served over HTTPS.
  • No accounts or payments. We never ask you to create an account, log in, or pay through the website.
  • Minimal collection. The call request form asks only for what we need to reach you and understand the request.
  • Analytics off by default. Google Analytics runs only if you allow it.

The Matcher

The Matcher is internal software. It is not available on the internet and there is no dealer login, portal or feed. It does not make offers or decisions on its own: a person at Silvara reviews every match.

Payment safety

We will never change payment instructions by email alone. Payment fraud that impersonates a broker or dealer is common in vehicle transactions. If you receive new or changed payment instructions that appear to come from us, call us on (204) 588-4057 before sending any money.

Payment for a vehicle is made by bank draft or wire as set out in the bill of sale, and we confirm payment before a vehicle moves.

If something goes wrong

If a breach of security safeguards involving personal information creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify the people affected as soon as feasible, and, for people in Quebec, notify the Commission d'accès à l'information where required. We keep a record of every incident for at least 24 months.

Report a vulnerability

If you believe you have found a security vulnerability in our website or systems, please tell us at miguel@silvaraautomotive.com with "Security report" in the subject line. Please include:

  • a description of the issue and where it is;
  • the steps needed to reproduce it;
  • how we can contact you.

We will acknowledge your report, keep you informed as we investigate, and fix confirmed issues as quickly as we can.

Testing in good faith

We will not pursue action against anyone who reports a vulnerability in good faith and follows these guidelines:

  • do not access, change or delete data that is not yours, and stop as soon as you reach any personal information;
  • do not degrade the site or our services, including by denial of service, spam or social engineering;
  • give us reasonable time to fix the issue before telling anyone else.

Our contact details for security researchers are also published at /.well-known/security.txt.