One dealership environment.
Store context, files, credentials, browser sessions, memory, activity records, and recovery copies are kept separate from other dealerships. Another store’s information is not used to answer your requests.
Security & privacy
DealerClaw earns access one workflow at a time. Your dealership context does not become a shared AI workspace.
DealerClaw is set up as a dedicated environment for each approved dealership scope. Access is limited to approved people, systems, workflows, and actions.
Store context, files, credentials, browser sessions, memory, activity records, and recovery copies are kept separate from other dealerships. Another store’s information is not used to answer your requests.
Every connection begins with a written dealership job. DealerClaw receives only the systems, records, fields, dates, and actions that job requires. CRM access starts read-only when the workflow allows it.
Users must be approved for the dealership scope. Shared logins are not accepted. Access is designed so one person can be removed without affecting other users.
The AI does not decide its own authority. Customer messages, record changes, large exports, pricing changes, and other consequential external actions require authorized human approval by default.
The CRM remains the system of record. DealerClaw limits the information used for each job. Customer PII stays out of long-term Store Brain memory by default.
DealerClaw records the request, approved scope, tools, approvals, result, and errors. Logs are designed to show what happened without becoming another broad copy of customer conversations.
Sensitive access release gate
Sensitive CRM access stays off until the complete workflow passes its security and privacy review. If a required control is not ready, the work stays limited to approved redacted exports, aggregate reports, or dealership-side de-identification.
Current assurance
DealerClaw is not currently SOC 2 examined or ISO/IEC 27001 certified.
Our security program is mapped to the NIST Cybersecurity Framework 2.0, NIST Privacy Framework, NIST AI Risk Management Framework, CIS Controls v8.1 Implementation Group 2, OWASP guidance for LLM applications, and FTC Safeguards Rule requirements relevant to dealers and their service providers.
These are frameworks and regulatory requirements—not DealerClaw certifications. For a sensitive connected workflow, a dealership can review the approved data scope, access matrix, retention schedule, service-provider list, security terms, incident route, offboarding steps, and current independent-assurance evidence.
This page describes DealerClaw’s security design and release requirements. The signed agreement and security exhibit control the exact production service.