Security

Enterprise-grade security for dealership data.

RooftopCommand is built to help dealer groups manage sensitive customer, vehicle, service, pricing, inventory, and operational data with security controls designed for role-based dealership environments.

Dealer-owned data

Role-based access

Rooftop-level controls

Audit-ready activity

Data ownership

Your dealership owns its data.

RooftopCommand does not sell dealer or customer data. Dealer data remains the property of the dealership or dealer group. Access, exports, retention, and offboarding are controlled through administrative permissions and documented policies.

Role-based access

Each role sees what its job requires — and nothing more.

Dealer principals, GMs, fixed ops directors, service managers, advisors, BDC, compliance, controllers, and consumers each see only the data appropriate to their role.

Dealer principal

Group-wide visibility across all rooftops

General manager

Rooftop / store-level performance

Fixed ops director

Service and repair recovery across assigned rooftops

Service advisor

Assigned customers, vehicles, repair opportunities, and tasks

BDC

Outreach tasks, recall campaigns, and customer follow-up

Compliance manager

Pricing risk, inventory risk, and audit activity

Controller / CFO

Billing, ROI, export controls, and reporting

Consumer owner

Only their own Customer Ownership Hub

Rooftop-level data isolation

Access can be restricted by group, rooftop, department, and role.

A staff member assigned to one rooftop does not automatically see another rooftop unless granted permission.

Level 1

Dealer group

Top-level operating entity

Level 2

Rooftop

Individual store / location

Level 3

Department

Sales · Fixed ops · BDC · Compliance

Level 4

Role

Title-level permissions within a department

Secure access

Authentication and session controls built for dealership environments.

HTTPS / TLS in transit

All RooftopCommand traffic is encrypted in transit using HTTPS / TLS.

Database encryption at rest

Sensitive dealer data is stored with database encryption at rest.

MFA-ready authentication

RooftopCommand is built to support multi-factor authentication for dealer users.

Secure password reset

Password resets are verified and time-bounded.

Secure invite flow

Dealer staff and consumers are added through verified invitation links.

Session timeout policies

Idle and maximum-session policies sign users out automatically.

Least-privilege access

Users default to the minimum access required for their role.

Audit logs

Audit-ready activity for sensitive actions.

RooftopCommand is designed to record sensitive actions so dealer principals, compliance managers, and controllers can review activity across rooftops.

  • Customer record viewed
  • Vehicle record edited
  • Service opportunity updated
  • Declined repair marked recovered
  • Recall opportunity updated
  • Pricing risk resolved
  • Inventory audit changed
  • Customer export generated
  • Document downloaded
  • User role changed
  • Admin settings changed

Export controls

Exports are permission-based and logged.

Administrators can control who can export customer, vehicle, service, campaign, inventory, pricing, and reporting data. Exports are permission-based and recorded in the audit trail.

Permission-based exports

Export rights are granted per user, per scope.

Logged in the audit trail

Every export records actor, scope, filters, and record count.

Sensitive data controls

Field-level visibility and least-privilege defaults.

Field-level masking for sensitive information

Document access permissions

Limited access to trade and payoff data

Limited access to financial data

Limited access to cost and gross data

Least-privilege permissions by default

Role-based visibility for service costs

Role-based visibility for sales opportunities

Role-based visibility for executive metrics

Compliance support

Designed to support dealership security and compliance workflows.

RooftopCommand is designed to support dealership security and compliance workflows, including data-access controls, audit trails, and documentation practices. RooftopCommand does not provide legal advice, and dealerships should review their legal, privacy, regulatory, and information-security obligations with qualified counsel and security professionals.

Dealer trust statement

RooftopCommand is built on a simple principle: dealer data belongs to the dealer. We do not monetize customer lists, sell consumer data, or expose rooftop-level operating data to unauthorized users.

Security FAQ

Common questions from dealer groups.

See it live

See the controls in a working dealer demo.

Request Dealer Demo