Security
Enterprise-grade security for dealership data.
RooftopCommand is built to help dealer groups manage sensitive customer, vehicle, service, pricing, inventory, and operational data with security controls designed for role-based dealership environments.
Dealer-owned data
Role-based access
Rooftop-level controls
Audit-ready activity
Data ownership
Your dealership owns its data.
RooftopCommand does not sell dealer or customer data. Dealer data remains the property of the dealership or dealer group. Access, exports, retention, and offboarding are controlled through administrative permissions and documented policies.
Role-based access
Each role sees what its job requires — and nothing more.
Dealer principals, GMs, fixed ops directors, service managers, advisors, BDC, compliance, controllers, and consumers each see only the data appropriate to their role.
Dealer principal
Group-wide visibility across all rooftops
General manager
Rooftop / store-level performance
Fixed ops director
Service and repair recovery across assigned rooftops
Service advisor
Assigned customers, vehicles, repair opportunities, and tasks
BDC
Outreach tasks, recall campaigns, and customer follow-up
Compliance manager
Pricing risk, inventory risk, and audit activity
Controller / CFO
Billing, ROI, export controls, and reporting
Consumer owner
Only their own Customer Ownership Hub
Rooftop-level data isolation
Access can be restricted by group, rooftop, department, and role.
A staff member assigned to one rooftop does not automatically see another rooftop unless granted permission.
Level 1
Dealer group
Top-level operating entity
Level 2
Rooftop
Individual store / location
Level 3
Department
Sales · Fixed ops · BDC · Compliance
Level 4
Role
Title-level permissions within a department
Secure access
Authentication and session controls built for dealership environments.
HTTPS / TLS in transit
All RooftopCommand traffic is encrypted in transit using HTTPS / TLS.
Database encryption at rest
Sensitive dealer data is stored with database encryption at rest.
MFA-ready authentication
RooftopCommand is built to support multi-factor authentication for dealer users.
Secure password reset
Password resets are verified and time-bounded.
Secure invite flow
Dealer staff and consumers are added through verified invitation links.
Session timeout policies
Idle and maximum-session policies sign users out automatically.
Least-privilege access
Users default to the minimum access required for their role.
Audit logs
Audit-ready activity for sensitive actions.
RooftopCommand is designed to record sensitive actions so dealer principals, compliance managers, and controllers can review activity across rooftops.
- Customer record viewed
- Vehicle record edited
- Service opportunity updated
- Declined repair marked recovered
- Recall opportunity updated
- Pricing risk resolved
- Inventory audit changed
- Customer export generated
- Document downloaded
- User role changed
- Admin settings changed
Export controls
Exports are permission-based and logged.
Administrators can control who can export customer, vehicle, service, campaign, inventory, pricing, and reporting data. Exports are permission-based and recorded in the audit trail.
Permission-based exports
Export rights are granted per user, per scope.
Logged in the audit trail
Every export records actor, scope, filters, and record count.
Sensitive data controls
Field-level visibility and least-privilege defaults.
Field-level masking for sensitive information
Document access permissions
Limited access to trade and payoff data
Limited access to financial data
Limited access to cost and gross data
Least-privilege permissions by default
Role-based visibility for service costs
Role-based visibility for sales opportunities
Role-based visibility for executive metrics
Compliance support
Designed to support dealership security and compliance workflows.
RooftopCommand is designed to support dealership security and compliance workflows, including data-access controls, audit trails, and documentation practices. RooftopCommand does not provide legal advice, and dealerships should review their legal, privacy, regulatory, and information-security obligations with qualified counsel and security professionals.
Dealer trust statement
RooftopCommand is built on a simple principle: dealer data belongs to the dealer. We do not monetize customer lists, sell consumer data, or expose rooftop-level operating data to unauthorized users.
Security FAQ
Common questions from dealer groups.
See it live
See the controls in a working dealer demo.


