How your store's data is protected.
A dealership's deals carry customer details and what the store earns on each one. This is what protects them today, in plain language, including what we have not done yet.
Your data
A separate database per store
Each store runs on its own database and its own deployment. One store's rows are not in another store's tables.
Read-only toward your DMS
Where a store connects its DMS, DealerCockpit reads. It has no way to write to the DMS, so nothing here can change what is booked or posted.
Recovery
The database keeps point-in-time recovery, and there is a written restore procedure. A restore drill is on the calendar every quarter.
Who can see and do what
Department and level
Every person belongs to a department and a level: staff, manager or executive. The department decides what they can see, the level decides what they can do inside it.
Gross stays hidden
Money columns are hidden from anyone without the permission to see gross. A salesperson works the deal without seeing what the store makes on it.
Changes take effect quickly
A deactivated person loses access within about a minute, even if they are signed in. A department move applies on their next request.
A delegate cannot reach an owner
People who are given the power to manage logins cannot edit, reset or promote an executive.
Signing in
Passwords are hashed
Passwords are stored as one-way hashes, never as text.
Signed sessions
Sessions are signed, HttpOnly, secure and last 30 days. Rotating the signing secret signs everyone out at once.
Rate limits
Sign-in attempts are limited per person and per network, so a guessing run stops early.
An optional second step
A person can turn on an emailed one-time code. It is optional today, so a store's real posture depends on people turning it on.
Sign-in links
A manager can send a single-use link that signs the person in once. Only a hash of it is stored, and it expires.
Records
An audit trail
Changes to deals, gross, permissions and settings are written with who made them, the old value and the new one. The app has no way to edit or delete an entry.
Kept for a set time
Audit entries are kept for a year by default and then aged out, with one exception: the desk's first quoted gross for each deal is kept, because the trail is the only place it survives.
Who else touches the data
These are the services that run the product. Each one is used for what its name suggests and nothing else.
Supabase
The database.
Vercel
Hosting.
Resend
Email such as reports, sign-in links and codes.
Anthropic
The Goose assistant, when someone asks it a question.
Sentry
Error tracking, with session replay masked.
What we do not claim
It is better you hear it from us.
Not certified
DealerCockpit is working toward a SOC 2 Type II report. It does not have one today.
A fuller review on request
A store that is evaluating DealerCockpit can ask for our security questionnaire and we will answer it in detail.
No status page yet
We do not publish an uptime page, because we would rather have real history behind one than a blank one.
Reporting a problem
If you find a security issue, write to hello@dealercockpit.app. Say what you found and how to reproduce it. We will answer.
See also the privacy page.
Try it in the beta.
DealerCockpit is in beta and we are looking for dealerships to try it as new features arrive. Not everything works as well as we plan yet.
