All Azure Technologies @ one Place
What does it take for a small startup to operate a secure, AI-driven platform on Azure? CarTrace.nl, an innovative car report service that combines a free licence plate check, European stolen vehicle searches, and an AI advisor, serves as an excellent real-life example. Built on Azure App Service, it is containerised, shielded by a Web Application Firewall (WAF) at the edge, and utilises its AI agent, Leo, through an AI hub approach, incorporating several models, capability-gated tools, and strict protocols for managing untrusted web content.
A Startup Inspired by a Stolen Car
CarTrace is a Dutch platform specialising in vehicle history reports, stolen vehicle verifications, and car buying advice. It originates from a common experience: the founder’s car was stolen near Utrecht, highlighting how fragmented vehicle and theft information can be across the Netherlands and Europe.
What makes CarTrace particularly noteworthy for this discussion is not just the product itself, but the underlying architecture: a compact team successfully operating a public, data-intensive, AI-supported platform on Azure, securing it without the resources of a large enterprise. It’s a compelling real-world case of the concepts I have been exploring in this series.
How CarTrace Operates: Architecture Influenced by Function
| Feature | Functionality | Architectural Influence |
|---|---|---|
| Licence Plate Check | Free checks for RDW data, APK history, recalls, and theft status. | Public, anonymous access with high traffic volumes. Attracts bots and scrapers. |
| Stolen Vehicle Map | Searches for stolen vehicles across Europe. | Handles sensitive data where integrity is paramount. |
| Leo AI | An AI car-buying advisor that provides answers based on actual vehicle data. | Calls to large language models (LLMs), content from the web, and memory introduce a new range of security challenges. |
| My Garage | Personal vehicle dashboard that offers maintenance alerts. | Managed user data with considerations for GDPR compliance. |
| Live Cameras | Network of traffic cameras for vehicle recovery. | Requires third-party data feeds and strict egress controls. |
CarTrace’s Unique Proposition: A New Era of Car Reports
While many car-check websites offer customers reports filled with registration details but leave them to interpret the data, CarTrace adopts a fresh approach, making its architecture noteworthy:
1The Comprehensive Check Consolidating Multiple Sources
Registration data from RDW, inspection histories, recalls, and theft status are compiled in a single licence plate check, complemented by stolen vehicle records from across Europe on the stolen vehicle map. Buyers benefit from a holistic overview rather than disparate pieces from multiple sites.
2An AI Advisor that References Its Sources
Instead of offering a static report, Leo engages users with straightforward responses: Is this a good purchase? What will the costs be? What common issues arise with this model? Every figure Leo provides is backed by a verifiable data source, ensuring claims are substantiated.
3Designed for Electric Vehicles
For used electric vehicles (EVs), a key concern is battery health. CarTrace estimates battery condition based on the car’s profile and can integrate this with official battery certifications, a step beyond traditional car reports.
5Your Car, Well Monitored
My Garage assists in managing the car you already own by providing maintenance alerts and reminders through a personal dashboard.
6Free Access to Start
The basic licence plate check is accessible without any account creation or payment, enabling anyone in the market for a used car to conduct a quick assessment.
This combination of public data, personal insights, theft information, and an interactive AI agent informs all the critical security decisions made by CarTrace.
Test it on your own vehicle
Enter any Dutch licence plate to discover what CarTrace can reveal: APK history, recalls, and theft status. It’s free, with no account required.
The Core Platform: Intentionally Simplistic
For startups, ideal architecture is the kind that operates smoothly without constant oversight. CarTrace’s foundational design is intentionally straightforward:
- ▸Next.js (App Router), deployed in containers and hosted on Azure App Service in Western Europe, ensuring proximity to its Dutch clientele and adherence to EU regulations.
- ▸PostgreSQL serves as the database for vehicle information, the stolen vehicle registry, and user-related data.
- ▸Multiple AI Models operate behind Leo, predominantly utilising Azure OpenAI deployments located within the EU (more details on this below).
- ▸Internationalisation was incorporated from the outset, recognising that the issue of stolen vehicles transcends borders.
Key TakeawayKeep resource-intensive processes out of the web container. Tasks like text-to-speech processing or ML scoring are assigned their own containers, ensuring that surges in AI-processing loads do not hinder the functionality of licence plate checks.
Web, Android, and iOS: A Unified Platform with Multiple Access Points
CarTrace is not limited to a web platform; it also features mobile applications for both Android and iOS. This is particularly useful when buyers need to assess a vehicle’s value while physically examining it at a dealership or with a private seller.
From an architecture standpoint, the mobile applications are merely additional clients of the same platform:
- ▸The apps connect to the identical backend APIs as the website, establishing a unified set of business logic and a single source of truth.
- ▸Mobile traffic undergoes the same protective measures through the edge and WAF as web traffic. An API behind a mobile application is still a public API, hence susceptible to scrapers.
- ▸Both Leo and the licence plate check function consistently across all devices, adhering to the same safeguards and rate limits.
- ▸No provider keys or secrets are integrated within the app. Any confidential information within an application package must be treated as publicly accessible.
The free licence plate check is particularly appealing to bots. Therefore, the edge layer is where CarTrace protects itself against such traffic:
Public Traffic Route
Visitor
→
Azure Front Door + WAF
→
App Service (Container)
→
PostgreSQL
- ▸Web Application Firewall employs Microsoft’s managed rule set to defend against OWASP-style vulnerabilities.
- ▸Bot Protection ensures genuine visitors are separated from scrapers harvesting vehicle data.
- ▸Rate Limiting is implemented on lookup endpoints to prevent any single aggressive client from degrading performance for others.
- ▸Traffic reaching the origin Server must pass through the edge, preventing any direct access that could evade the WAF.
Layer 2: The AI Hub for Leo
Leo’s architecture is where things become intriguing. As an agent that searches the web, interprets content, and retains user information, Leo requires more than just an API key and a prompt. CarTrace has designated everything associated with Leo as a mini AI hub: a controlled network through which all model calls, tool uses, and external content flows.
Leo Request Path
User Inquiry
→
Leo Agent
→
AI Gateway (Routing, Limits, Logging)
→
Multiple Models (Azure OpenAI + Others)
Leo Tool Path
Leo Agent
→
Capability-Gated Tools
→
RDW Open Data · CarTrace Database · Approved Web Sources
The design principles that establish Leo’s reliability include:
- ▸All data must be verifiable to a tool result and a specific source. Should Leo be unable to source a claim, it will not present it.
- ▸Capability-Gated Tools. Each tool can be disabled, and the user interface explicitly identifies when a tool is unavailable instead of masking it.
- ▸External material is designated as untrusted by default. Web pages retrieved are enclosed, marked as untrusted, and scanned for potential prompt manipulations prior to processing.
- ▸Web searches are restricted to a curated list of allowable domains rather than unrestricted internet searches.
- ▸A defined step budget is allocated for each agent operation, ensuring that a confused agent cannot enter into an endless loop or exhaust token allowances.
- ▸Memory is meticulously extracted. The component responsible for determining what Leo retains never has direct visibility of raw tool output, ensuring that injected content from a web page cannot influence what the user remembers.
The Benefits of Running Multiple Models
Leo operates using more than one model or provider. The AI gateway efficiently directs inquiries across various model deployments, with Azure OpenAI in the EU as the primary option. This approach is a strategic decision for enhancing security and resilience:
- ▸No single point of failure exists. Should one model experience throttling, degradation, or become unavailable, traffic can shift instead of Leo becoming non-functional.
- ▸Separation of responsibilities is key. The model tasked with filtering untrusted content is distinct from the one addressing user inquiries, meaning a prompt-injection tactic tailored to one model cannot easily transfer to another.
- ▸Avoidance of lock-in with any single provider’s vulnerabilities. Exploitation techniques, jailbreaks, and outages can often be relevant to only one model, hence a mix of models dilutes the effectiveness of a single exploit.
- ▸Models are appropriately sized for their tasks. Smaller, economically efficient models can handle classification and screening, while larger models tackle reasoning tasks. This strategy also limits the potential costs associated with misuse.
Architecture Insight The utility of multiple models is maximised only when the gateway, rather than the application code itself, determines which model is applied to which request. Failure to do so means every new model introduces another integration that must be secured.
The Importance of This Approach Prompt injection is analogous to SQL injection in the realm of AI. The initial version of any agent typically harbours some vulnerabilities. Leo’s design preemptively accounts for vulnerabilities, ensuring that no single flaw can breach the entire system. When such flaws are identified, the architecture is rectified rather than merely fixing symptoms.
Discover Leo
Consult Leo regarding any vehicle you are considering: operational costs, common issues, recalls, and battery health for EVs. Every piece of information comes with a source citation.
Layer 3: Managing Identity and Secrets
- ▸Utilise managed identities wherever Azure permits to facilitate inter-service communication without requiring stored passwords.
- ▸Store all remaining secrets (payment details and third-party API keys) within Azure Key Vault, never embedding them in container images or repositories.
- ▸Implement least-privilege database roles: the public licence plate check only allows read access; back-end tasks are granted write permissions.
Layer 4: Ensuring Data Protection and Privacy
- ▸Data remains within the EU: tasks are processed in Western Europe, utilising EU-hosted models as the default for Leo.
- ▸Only essential information for each feature is retained. The licence plate check can be executed without requiring account creation.
- ▸Third-party data sources are treated as potentially unreliable: external queries are safeguarded by circuit breakers, preventing sluggish partners from impacting overall site performance.
How Startups Can Implement This Approach
Establishing security measures does not necessitate a fully-fledged corporate structure on day one. I recommend the CarTrace methodology for any startup:
| Initial Setup | Enhancements as You Scale |
|---|---|
| WAF + rate limiting at the edge | Advanced bot management and geographical rules |
| Managed identities + Key Vault | Private endpoints for databases and AI services |
| Agent guardrails in code (allow-lists, step budgets, untrusted content) | A comprehensive AI gateway with individual token allowances per feature |
| Dedicated containers for resource-intensive tasks | Distinct environments and subscriptions for production and non-production stages |
My Perspective
CarTrace emerged from a personal challenge, yet the architectural insights gleaned are universally applicable. Ensure a WAF is positioned in front of any publicly accessible feature. Treat your AI agent as a distinct, regulated entity complete with its own gateway, rules, and resource budgets. Avoid reliance on a single model and assume external sources are untrustworthy, especially textual data that an LLM will process. Finally, maintain a streamlined core architecture so the team can devote their efforts towards enhancing the product.
If you’re looking to purchase a used car in the Netherlands or want to verify if a vehicle has been reported stolen, CarTrace is definitely worth exploring. For those embarking on creating an AI-driven startup on Azure, I hope this framework assists you in averting some late-night challenges.
Disclosure: My involvement with CarTrace is substantial.
Assess a vehicle before making a purchase
APK history, recalls, theft status, and an AI advisor that confirms its references. Developed on Azure and created in the Netherlands.
Frequently Asked Questions (FAQ)
What is CarTrace?
Can I determine if a car has been stolen?
Does CarTrace support electric vehicles?
Is there an app for CarTrace?
Which cloud services does CarTrace utilise?
Microsoft Azure: running containers on App Service within Western Europe, complemented by EU-hosted AI models through a governed AI gateway.
Share this content:
Discover more from Qureshi
Subscribe to get the latest posts sent to your email.



