How your store's data is protected.

A dealership's deals carry customer details and what the store earns on each one. This is what protects them today, in plain language, including what we have not done yet.

Your data

  • A separate database per store

    Each store runs on its own database and its own deployment. One store's rows are not in another store's tables.

  • Read-only toward your DMS

    Where a store connects its DMS, DealerCockpit reads. It has no way to write to the DMS, so nothing here can change what is booked or posted.

  • Recovery

    The database keeps point-in-time recovery, and there is a written restore procedure. A restore drill is on the calendar every quarter.

Who can see and do what

  • Department and level

    Every person belongs to a department and a level: staff, manager or executive. The department decides what they can see, the level decides what they can do inside it.

  • Gross stays hidden

    Money columns are hidden from anyone without the permission to see gross. A salesperson works the deal without seeing what the store makes on it.

  • Changes take effect quickly

    A deactivated person loses access within about a minute, even if they are signed in. A department move applies on their next request.

  • A delegate cannot reach an owner

    People who are given the power to manage logins cannot edit, reset or promote an executive.

Signing in

  • Passwords are hashed

    Passwords are stored as one-way hashes, never as text.

  • Signed sessions

    Sessions are signed, HttpOnly, secure and last 30 days. Rotating the signing secret signs everyone out at once.

  • Rate limits

    Sign-in attempts are limited per person and per network, so a guessing run stops early.

  • An optional second step

    A person can turn on an emailed one-time code. It is optional today, so a store's real posture depends on people turning it on.

  • Sign-in links

    A manager can send a single-use link that signs the person in once. Only a hash of it is stored, and it expires.

Records

  • An audit trail

    Changes to deals, gross, permissions and settings are written with who made them, the old value and the new one. The app has no way to edit or delete an entry.

  • Kept for a set time

    Audit entries are kept for a year by default and then aged out, with one exception: the desk's first quoted gross for each deal is kept, because the trail is the only place it survives.

Who else touches the data

These are the services that run the product. Each one is used for what its name suggests and nothing else.

  • Supabase

    The database.

  • Vercel

    Hosting.

  • Resend

    Email such as reports, sign-in links and codes.

  • Anthropic

    The Goose assistant, when someone asks it a question.

  • Sentry

    Error tracking, with session replay masked.

What we do not claim

It is better you hear it from us.

  • Not certified

    DealerCockpit is working toward a SOC 2 Type II report. It does not have one today.

  • A fuller review on request

    A store that is evaluating DealerCockpit can ask for our security questionnaire and we will answer it in detail.

  • No status page yet

    We do not publish an uptime page, because we would rather have real history behind one than a blank one.

Reporting a problem

If you find a security issue, write to hello@dealercockpit.app. Say what you found and how to reproduce it. We will answer.

See also the privacy page.

Try it in the beta.

DealerCockpit is in beta and we are looking for dealerships to try it as new features arrive. Not everything works as well as we plan yet.