Mon - Sat: 9:00 AM - 6:00 PM
Call: 844-376-2274
Guides
DMS Security Due Diligence Checklist
What to ask a dealer management system vendor before you hand them every customer record your store owns.
Why this lands on you and not on the vendor
A dealership holds an unusually rich pile of consumer data for its size. Full names, addresses, dates of birth, driver license images, Social Security numbers on credit applications, income statements, bank details on payoffs, and years of communication history. Most of it sits in or flows through the dealer management system.
Federal rules covering financial institutions have been read to include car dealers that arrange financing, which is why the Safeguards Rule conversation reached the industry at all. A recurring theme in those obligations is service provider oversight: it is not enough to pick a vendor and assume they handle it. You are generally expected to select providers capable of protecting the data, to say so contractually, and to keep checking. Rules and interpretations change, and the specifics vary by state and by how your store is structured, so treat this page as a starting checklist and confirm your own obligations with counsel or a qualified compliance advisor. We are a software vendor, not your lawyer.
The practical point stands whatever the current rule text says. When a vendor is breached, the notification letters go out with your store's name on them, your customers call your number, and your reputation absorbs it. Due diligence is not paperwork for its own sake. It is the only leverage you have, and you only have it before you sign. Our Safeguards Rule overview covers the broader program side.
Ask for evidence, not assurances
Every vendor says they take security seriously. That sentence carries no information. What separates vendors is whether they will hand you documents.
Ask for an independent audit report and read the scope section rather than the cover page. A report can be real and still exclude the specific system you are buying, or cover a period that ended two years ago. Check the dates, the systems in scope, and the list of exceptions the auditor noted. A vendor with nothing to hide will let you read it under an NDA. A vendor who will only show you a logo on a marketing page is telling you something.
Ask when the last independent penetration test was run, by whom, and whether findings were remediated. You will not get the raw report and should not expect to, but a summary letter is normal. Ask whether they run a vulnerability management program and what their patching window looks like for critical issues.
Ask where the data physically lives, which country, and whether any subcontractor touches it. Cloud hosting is fine and normal. Undisclosed subprocessors are not. Get the subprocessor list in writing and ask to be notified when it changes, because a vendor's supply chain is now part of your risk whether or not anyone told you.
Write down every answer with a date and the name of the person who gave it. Vendor staff turn over, and a promise nobody recorded is a promise nobody made.
Access control is where most stores actually leak
Sophisticated attacks make the news. Ordinary account hygiene causes most of the damage in dealerships, and it is the part you control rather than the vendor.
Start with the offboarding question, because it is the single most revealing one you can ask your own management team: when a salesperson quit last month, how long did their login keep working? In a lot of stores the honest answer is that nobody knows, or that it still works. A departing employee with an active login and a customer list is a real exposure, and it is entirely a process failure.
Then look at shared accounts. A single desk login that four managers use destroys accountability, because no log can tell you who did anything. If your vendor makes per user accounts expensive, that pricing decision is quietly buying you an audit problem.
Ask the vendor whether multi factor authentication is available, whether it can be enforced rather than merely offered, and whether it applies to administrative accounts and remote access. Ask whether permissions are genuinely role based, so a lot porter cannot pull a full customer export. Ask whether there is a login log and an activity log you can read yourself without opening a support ticket, and how long those logs are retained.
Finally, ask what mass export looks like. If any user with a browser can download the entire customer database in one click and nobody is alerted, you have a data loss problem that no encryption claim addresses.
Encryption, backups and the questions behind them
Vendors will confirm encryption in transit and at rest quickly, because the answer is almost always yes and it sounds reassuring. Push one layer past it.
For data in transit, ask which protocol versions are still accepted. Old versions left enabled for the sake of one legacy integration undo the modern configuration. For data at rest, ask what is actually encrypted. Whole disk encryption protects against a stolen drive and does very little against an attacker with valid application credentials. Field level protection on the sensitive items is a different and stronger claim.
Ask who holds the keys and who can decrypt. If any vendor employee can read your customers' Social Security numbers on demand, that is worth knowing before you decide, not after.
Backups deserve their own set of questions and they rarely get asked. How often, how long retained, encrypted, and stored where. Most importantly: when was a restore last actually tested, and how long did it take end to end? A backup nobody has restored is a hypothesis. Ransomware planning lives here too. Ask whether backups are immutable or otherwise isolated, because a backup an attacker can encrypt alongside production is not a recovery plan.
Ask what the recovery time and recovery point objectives are, in hours, in writing. Then ask what your store does for those hours, because the answer to that one is yours to build.
Every integration is a door
The system is rarely breached in isolation. It is reached through something connected to it, and dealerships connect a lot of things.
Build the inventory before you shop. Write down every third party that reads from or writes to the system today: inventory syndication, the website provider, lead providers, chat, desking, F&I products, marketing vendors, analytics, reputation tools, and any consultant with a login. Most stores are surprised by the length of that list, and by how many entries nobody can explain the origin of.
For each one, ask three things. What data does it receive, at what level of detail? How is it authenticated, and can that credential be rotated without breaking the connection? Who at the store approved it, and is that person still here?
Then ask the vendor whether integration access is scoped. A partner needing inventory should not be able to read finance data. If every integration uses one credential with full access, you have a single key that opens every room, held by a dozen companies of varying quality.
Ask how integration access is revoked and how quickly. When you fire a marketing vendor, their access should die the same day. Ask who at the vendor can turn on a new data connection to your store, and whether they will notify you when someone does. Our integration inventory template gives you a structure for the list, and privacy request management covers the consumer facing side.
Incident response, notification and the contract
Assume something will go wrong somewhere in your vendor chain eventually. The questions that matter are about what happens next, and most of them are contract questions rather than technical ones.
How quickly will the vendor notify you, in hours, counted from discovery rather than from confirmation? Vague language such as promptly or without undue delay means the timing is theirs to decide. Ask for a number.
Who notifies affected consumers, and who pays for it? Notification costs money: mailing, call center capacity, credit monitoring, legal review. State breach notification laws differ and some carry tight deadlines, so know in advance whose obligation this is under your contract.
What forensic support does the vendor provide, and will you get a written incident report or a phone call and a summary? Does the vendor carry cyber liability insurance, at what limit, and are you named or otherwise protected? Is there a limitation of liability clause that caps their exposure at three months of fees, which is common and which effectively means the financial risk is entirely yours?
Also ask what their notification obligation is when a subprocessor is breached rather than the vendor itself. That gap has caught plenty of businesses out.
None of this is negotiable after signature. All of it is at least discussable before, which is the whole argument for doing the work while you still have a choice. The contract checklist covers the commercial terms that sit alongside these.
Data ownership and the exit you have not planned yet
Security due diligence and exit due diligence are the same conversation, because a vendor that will not let your data leave has effectively taken custody of it.
Ask, and get it in writing: who owns the data in the system. The answer should be your store. Ask what you can export, in what formats, and whether it includes the things that are painful to lose, which are notes, communication history, attached documents and the audit trail rather than the name and address list everyone will happily give you.
Ask whether export is self service or a paid professional services engagement, and what that costs. Ask how much notice is required to terminate and what access you retain during the wind down. Ask what happens to your data after termination: is it deleted, on what schedule, and will you get written confirmation? Backups complicate this and an honest vendor will say so rather than claiming instant erasure.
Run a test export in the first month of the relationship, not in the last. The month you decide to leave is the worst possible time to discover the format is unusable. Our page on dealership data ownership works through this in more depth, and the exit plan guide covers sequencing.
The checklist, in order
Work through this before signature. Assign an owner to each line, because a checklist with no name against an item does not get done.
- Independent audit report obtained and the scope section read, not just the cover.
- Date and summary of the most recent independent penetration test, plus remediation status.
- Written subprocessor list, with notification of changes.
- Hosting locations named, including any offshore processing or support access.
- Multi factor authentication available and enforceable, including for administrators.
- Role based permissions demonstrated in a live screen, not described in a slide.
- Login and activity logs readable by you, with a stated retention period.
- Bulk export capability restricted and alerted.
- Encryption in transit and at rest, with the field level question asked specifically.
- Backup frequency, retention, isolation, and the date of the last tested restore.
- Stated recovery time and recovery point objectives in hours.
- Full integration inventory built, with data scope and credential rotation for each.
- Breach notification window stated in hours from discovery.
- Consumer notification responsibility and cost allocation agreed.
- Cyber liability insurance limit confirmed and the liability cap read.
- Data ownership, export scope and post termination deletion in writing.
- Internal offboarding process that kills every login the day someone leaves.
Seventeen lines. A couple of afternoons of work against a system you will run for a decade. The vendor evaluation scorecard gives you somewhere to record the answers.
Where LeadLocate sits in this picture
Plainly: we do not sell a dealer management system. No general ledger, no accounts payable or receivable, no payroll, no deal posting to accounting, no parts, no repair orders, no title or registration work. If you are shopping for one, evaluate it on its own merits with the checklist above.
What we run is the lead generation, communication and CRM layer that sits beside whatever system your store uses, and the same due diligence questions apply to us. So here is our own side of it. Customer profiles hold sensitive personal information encrypted, with opaque tokens rather than raw identifiers in the places that would otherwise leak them. User management is role based, so permissions can be narrowed by job. There is a login log. Opt out status is honored across every channel on the platform rather than per module, which is a compliance issue as much as a courtesy. On the finance intake side, SecureWebX handles secure credit applications, apply links, document collection, identity verification at intake, and a compliance module with versioned consent, so you can show what a customer agreed to and which version of the language they saw.
What we do not claim: we are not an OEM certified system, we hold no security certification we have not shown you, and no DMS integration is required to operate, which limits the blast radius in both directions. Ask us the same seventeen questions you ask everyone else. Contact us and we will answer them in writing.
Frequently Asked Questions
Does LeadLocate sell a dealer management system?
No. There is no accounting, parts, repair order, payroll or title and registration function, and we do not claim otherwise. We provide the lead generation, communication and CRM layer that runs alongside whichever system your store uses.
What is the single most useful question to ask a vendor?
Ask for the independent audit report and read the scope section. It tells you whether the system you are buying was actually assessed, over what period, and what exceptions the auditor recorded. Marketing pages never carry that detail.
Is this page legal or compliance advice?
No. It is a buyer education checklist. Obligations differ by state, by how your store arranges financing and by current interpretation of the rules, so confirm what applies to you with counsel or a qualified compliance advisor.
How often should due diligence be repeated?
Most stores that do this well review vendors annually and again whenever a vendor changes ownership, changes hosting or adds a subprocessor. Ownership changes are worth watching because security posture and support quality often change with them.
What is the most commonly missed item?
Employee offboarding. Logins that stay active after someone leaves cause more real exposure in dealerships than exotic attacks do, and it is entirely within the store's control rather than the vendor's.
Why does an exit clause belong in a security review?
Because a vendor who will not release your data in a usable format has taken practical custody of it. Test an export in your first month so you find out the format works while you still have a good relationship.
Ask us the same seventeen questions
We will answer the security, access and export questions in writing before you commit to anything. Month to month, no long term contract, and your data leaves with you.


LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.
Answers to your questions:
LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.
LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.
Answers to your questions:
LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.



