Mon - Sat: 9:00 AM - 6:00 PM
Call: 844-376-2274
CRM & Software
Automotive CRM Security Checklist
Your CRM holds more personal information than any other system in the store. Here is what to lock down, in the order that matters.
Start by admitting what is in there
Most dealers think of the CRM as a sales tool and think of security as an accounting or F and I problem. That is backwards. Your CRM usually holds more personal information about more people than any other system in the building, and it is the system with the most user accounts and the highest staff turnover attached to it.
Take an honest inventory. Names, home addresses, mobile numbers and email addresses for tens of thousands of households. Full text and email conversation history. Call recordings and transcripts. Photographs of driver licenses and insurance cards that somebody attached to a deal because it was convenient. Trade payoff information. Vehicle and household details. Notes that staff wrote assuming nobody outside the store would ever read them.
Now consider who can reach all of that. Every salesperson with a login, including the three who left last quarter if nobody disabled them. Everyone with the shared front desk password. Any vendor given access for an integration two years ago that nobody has reviewed since.
That gap between what the system holds and who can reach it is the entire subject of this page. Nothing here is exotic. It is the boring work that prevents the incident, and it is almost always cheaper than the incident.
Access control: least privilege, actually applied
The principle is simple and the practice is where stores fail. Every person gets exactly the access their job requires and nothing more, and that is decided by role rather than by whoever asked loudest.
Write your roles down before you configure anything. A salesperson needs their own customers and the ability to work leads assigned to them. A BDC agent needs the queue they cover. A sales manager needs their team plus deal detail. A used car director needs inventory and used deals, but probably not new car gross. An owner needs everything. An outside agency needs reporting with no customer contact data at all.
LeadLocate supports role based user management with per user access control, so these are configuration decisions rather than compromises. Decide the model during setup rather than retrofitting it onto two hundred live users later, which is a far more painful project than it sounds.
Two specific things to check. First, whether a user can export. Bulk export is the single highest risk permission in any CRM, because it converts controlled access into a file on a laptop, and it should be limited to a named short list. Second, whether anyone is sharing a login. Shared accounts destroy accountability, and after any incident the first question is who did this, which a shared login makes unanswerable.
Offboarding is where dealerships lose data
Turnover in automotive retail is high, and the most common real world data loss at a dealership is not a hacker. It is a salesperson who left for the store across town with a copy of the customer list.
Build a written offboarding routine and run it on the last day, not the following week. Disable the CRM login immediately. Disable email and phone access. Reassign their customer records deliberately rather than dumping everything into one manager's queue, which is functionally the same as deleting it. Review what they exported or downloaded in their final thirty days. Change any shared credential they knew.
The login log matters here, and it is why it exists. Knowing who logged in, when and from where is what turns a suspicion into a fact. Most stores never look at it until the week somebody leaves for a competitor, which is exactly the week it is worth looking at.
One thing to fix in your paperwork rather than your software. Make sure your employment agreements are clear about customer data ownership and about what an employee may take with them, which is nothing. Software controls the access. The agreement is what gives you a position afterward.
Run a full access review quarterly regardless of turnover. Every active login, every role, every vendor account, checked against a current staff list. It takes an hour and it consistently finds accounts that should not exist.
How the data is stored, transmitted and logged
These are the questions to put to any vendor in writing, including us.
Encryption at rest. Is personally identifiable information encrypted where it is stored, or only the connection to it? In LeadLocate, the customer profile stores personally identifiable information encrypted, and customer facing links use opaque tokens rather than sequential record numbers, which prevents the oldest trick in the book: changing a number in a URL to see somebody else's record.
Encryption in transit. Every page, every mobile view, every integration endpoint. Not just the login screen.
Logging. What actions are recorded, who can read the log, and how long is it kept. A login log tells you about access. Activity logging tells you about what was done with it. You want both.
Backups. How often, where they are held, whether they are encrypted, and whether anyone has ever restored one. A backup that has never been tested is a hope, not a control.
Deletion. What happens to your data when you leave, how long the vendor keeps it, and whether you can require deletion. Ask before you sign. Dealership data ownership covers the contract side of the same question.
The rules that already apply to your store
Dealerships are treated as financial institutions for several federal purposes, and the obligations attach whether or not anyone in the building has read them.
The Safeguards Rule requires a written information security program with a qualified person responsible for it, a risk assessment, access controls, encryption, vendor oversight, staff training and an incident response plan. Customer information in your CRM is squarely inside its scope, and a vendor's certifications do not discharge your obligation to oversee that vendor.
The Red Flags Rule requires an identity theft prevention program covering how you detect and respond to indicators of identity theft in your customer relationships.
State privacy laws add more depending on where you operate, including consumer rights to know, delete and opt out of certain data uses. Several states now have comprehensive privacy statutes and the list keeps growing, so this is worth a periodic conversation with counsel rather than a one time review.
Then the messaging rules, which are security adjacent and enforced more aggressively than most of the above. Consent before contact, immediate honoring of opt outs, and records that prove both. Losing a consent record in a system change is a real exposure and one of the most common ways stores create their own problem.
None of this is legal advice. It is a list of the conversations to have with your own counsel.
Mobile, personal devices and the shadow CRM
Here is the exposure nobody puts on a checklist. Your salespeople are texting customers from their personal phones, and those conversations are invisible to you.
When a salesperson works a customer on their own number, the store has no record of what was promised, no consent trail, no opt out handling, and no ability to reassign that relationship when the salesperson leaves. The customer relationship walks out the door in their pocket. From a compliance standpoint you cannot produce records you never had, and from a security standpoint the data is on a device you do not control.
The fix is not a policy memo. It is making the sanctioned tool faster than the personal phone. If texting from the CRM on a phone takes four taps and texting from the personal number takes one, the policy loses every time. That is why the mobile workspace and mobile messaging exist, and it is worth testing yourself on your own phone rather than assuming.
While you are looking at mobile, check what happens when a device is lost. Screen lock requirements, whether sessions expire, and how quickly you can cut a user off entirely. The answer should be that disabling the login in one place ends access everywhere, immediately.
Vendor and integration risk
Every integration is a door. Inventory providers, website vendors, third party lead sources, chat services, phone systems, marketing agencies. Each one has some level of access to your customer data and each one is a link in your chain.
Keep a written list of every vendor with access, what data they can reach, who at your store authorized it and when it was last reviewed. Most dealerships cannot produce that list today, and building it is usually the single most revealing hour in a security review because it surfaces two or three connections nobody remembered.
For each vendor, get the basics in writing: their security posture, whether they subcontract processing, breach notification timelines, and what they do with your data at termination. The Safeguards Rule expects this oversight from you, not from them.
Then remove what you are not using. Old API keys, dormant integrations, agency accounts from a relationship that ended. Access granted in 2022 for a project that finished in 2022 is pure risk with no remaining benefit. Security due diligence covers the same questions when evaluating a major system vendor.
The checklist, condensed
Print this and work down it. Anything you cannot answer today is where to start.
- Roles are written down and every user is assigned to one. No shared logins anywhere.
- Export permission is restricted to a named short list of people.
- Offboarding is a written routine executed on the last day, including record reassignment and a review of recent downloads.
- A quarterly access review compares every active login against a current staff list.
- Personal information is encrypted at rest and in transit, and customer facing links do not expose sequential record numbers.
- Login and activity logging is on, retained, and somebody actually reads it.
- Backups exist, are encrypted, and a restore has been tested at least once.
- Consent and opt out records are complete, dated and survive any system change.
- A written vendor list exists with data access, authorization and last review date for each.
- Staff text customers through the platform rather than personal phones, because the sanctioned path is genuinely faster.
- You have a written information security program, a named responsible person and an incident response plan.
- Your vendor contract states who owns the data, what you can export, and what happens to it when you leave.
LeadLocate covers the platform side of this with role based user management and per user access control, a login log, encrypted personally identifiable information on the customer profile, opaque tokens on customer facing pages, blacklist and opt out handling that applies across channels, and a versioned consent gate on the SecureWebX side for applications and disclosures. The organizational half, meaning offboarding discipline and vendor oversight, belongs to your store no matter which vendor you choose. CRM Only is $199 a month, month to month, and current figures are on the pricing page.
Frequently Asked Questions
What is the highest risk permission in a dealership CRM?
Bulk export. It converts controlled access into a file on somebody's laptop that you can no longer see or revoke. Restrict it to a named short list, log it, and review recent exports as part of every offboarding.
How often should we review user access?
Quarterly at minimum, comparing every active login against a current staff list, plus immediately whenever someone leaves. Most stores that run this review for the first time find accounts belonging to people who left months ago.
Does the Safeguards Rule apply to our CRM?
Customer information held in a CRM is generally within scope for a dealership, which is treated as a financial institution for this purpose. It requires a written program, a named responsible person, access controls, encryption, vendor oversight and an incident response plan. Confirm specifics with your counsel.
How does LeadLocate protect customer information?
Role based user management with per user access control, a login log, personally identifiable information stored encrypted on the customer profile, opaque tokens on customer facing links so record numbers cannot be guessed, and opt out handling that applies across channels.
What about salespeople texting from personal phones?
It is a real exposure: no record of what was promised, no consent trail, no opt out handling, and the relationship leaves with the employee. Policy alone does not fix it. The in platform path has to be faster than the personal phone or staff will keep using the phone.
What should we ask a CRM vendor about security before signing?
Encryption at rest and in transit, what is logged and for how long, backup and restore testing, subcontracted processing, breach notification timelines, who owns the data, what you can export, and what happens to your data after termination. Get it in writing.
See the access controls before you see the sales pitch
Ask us to walk the permission model, the login log and the encryption story first. Then look at the selling tools. Month to month, no long term contract.


LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.
Answers to your questions:
LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.
LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.
Answers to your questions:
LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.



