SW Sovereignware

Compliance  /  Auto dealerships

By practice · Automotive retail

Your dealership is a financial institution.

Not colloquially — under the Gramm-Leach-Bliley Act. If your store arranges or extends financing, the FTC treats it as a financial institution, and the Safeguards Rule applies to every deal jacket, credit application, and trade appraisal that carries a customer's nonpublic personal information. Most dealers learn this during an examination or after a breach. This page is what to know before either.

Posture statement · Not legal advice · See disclaimer below

Who this applies to

GLBA · 16 CFR Part 314 · FTC Safeguards Rule

The FTC treats auto dealers that arrange or extend financing — including assigning retail installment contracts to a lender — as financial institutions under GLBA. That places the store inside the Safeguards Rule. Dealers who sell strictly for cash and never arrange financing are generally outside it. Which side of that line a specific store sits on is a question for its own counsel.

The rule's practical demands are concrete: a written information security program with a named qualified individual, access controls, encryption of customer information in transit and at rest, multi-factor authentication on systems holding customer information, and — the clause that catches most stores — documented oversight of every service provider that handles customer information.

The AI-shaped hazard: the moment a salesperson pastes a credit application, a driver's licence, or a deal jacket into a general-purpose AI assistant, customer information has left the store and entered a service provider the dealer has not contracted, configured, assessed, or documented. It is fast, it is useful, and it is exactly the exposure the amended rule was written to address.

Primary source: FTC — Gramm-Leach-Bliley Act

The Red Flags Rule

Federal · 16 CFR Part 681 · FTC

Separately from Safeguards, covered creditors must maintain a written Identity Theft Prevention Program: identify relevant red flags, detect them in day-to-day operations, respond appropriately, and update the program periodically with senior-management or board oversight.

For a store, the red flags are operational rather than theoretical — a licence that does not match the credit application, an address that appears across unrelated deals, a buyer who cannot answer verification questions about their own file.

Architectural alignment: detection is a records problem before it is a policy problem. When every document in a deal is filed, fingerprinted, and searchable inside the store, the pattern across files is visible. When documents live in a shared drive, an email thread, and a filing cabinet, it is not.

Primary source: FTC — Red Flags Rule

The deal jacket is the compliance artifact

Operational · Titles, tags, and the paper behind a sale

A dealership's regulatory exposure is not abstract; it is a stack of paper per vehicle. Bill of sale, credit application, title work, odometer statement, buyer's guide, tag and transfer paperwork, payoff documentation on a trade. Each has a deadline and a retention obligation, and each carries nonpublic personal information.

What a sovereign deployment does with it

Why this is a compliance posture and not a filing cabinet: the same act that stores a document also proves it. Retrieval and verification are one operation, so a record produced for an examiner carries the fingerprint it was sealed with.

What we do not claim

Read this part especially

Sovereignware does not make a dealership compliant. Compliance is a program — written, staffed, trained, tested, and overseen — and no software supplies that. What the architecture supplies is evidence: records that can be shown to be unaltered, a chain of custody for the documents behind a deal, and a materially smaller service-provider surface to oversee, because customer information is not being handed to a third-party AI vendor in the first place.

We have not been audited, accredited, or certified by the FTC or any standards body. A dealer's obligations remain the dealer's, and whether this architecture suits a specific store is a decision for that store's counsel and compliance officer.

The honest version of the pitch: we assist with evidence. We do not certify, and we do not guarantee an outcome. Any vendor telling a dealer otherwise is selling something that will not survive an examination.

Important — what this page is, and what it is not.

This page documents Sovereignware™'s architectural alignment with the regulations discussed above. It is a posture statement, not a certification claim. We have not been audited, accredited, or certified by any government agency, standards body, or third-party assessor referenced here. Our customers' regulatory obligations are their own, and the appropriateness of Sovereignware™ for any specific compliance use case must be evaluated by the customer's own counsel and compliance officers.

Nothing on this page constitutes legal, regulatory, or compliance advice. Primary sources are linked above and should be consulted directly.

Related: the full regulatory posture · law firms & privilege