Security & privacy

How LotPro separates staff and customer data.

Dealership work stays tenant-scoped. Shared quote pages receive separate published records containing approved fields.

No certification claimedCurrent public status
Controls and current status

Decide what a page can receive before it renders.

Data minimization, tenant boundaries, separate shared records, and accountable server paths shape the product.

ControlCurrent public status
Tenant boundariesDealership and store scope is required for tenant data; deployment verification remains rollout-specific.
Customer quote recordsShared quote pages receive separate server-written records containing approved fields rather than the full staff record.
Payment-card dataThis site has no card fields or checkout. Any future card entry must remain on the payment processor’s hosted page.
Sensitive changesMoney, status, permission, and sensitive-data changes require accountable server paths and durable audit evidence.
Public assuranceNo certification or blanket legal-compliance claim is made on this site.
Customer-ready quote views

Hidden fields are still delivered fields.

LotPro separates the staff workspace from the published quote. The customer page receives an opaque session and a server-written record containing approved fields—not the entire deal with a few columns concealed.

Read the build note
01 · PRIVATEStaff workspaceWorking data + controls
02 · PUBLISHEDCustomer viewApproved fields only
Current status

No certification is claimed on this site.

Regulatory applicability, contractual requirements, technical controls, and deployment evidence must be reviewed for each dealership and launch.

Security-sensitive implementation details are not published on this marketing site. Current capabilities and verification status are confirmed during a launch review.