Who this applies to
GLBA · 16 CFR Part 314 · FTC Safeguards Rule
The FTC treats auto dealers that arrange or extend financing — including assigning retail installment
contracts to a lender — as financial institutions under GLBA. That places the store inside the
Safeguards Rule. Dealers who sell strictly for cash and never arrange financing are generally outside
it. Which side of that line a specific store sits on is a question for its own counsel.
The rule's practical demands are concrete: a written information security program with a named
qualified individual, access controls, encryption of customer information in transit and at rest,
multi-factor authentication on systems holding customer information, and — the clause that catches
most stores — documented oversight of every service provider that handles customer
information.
The AI-shaped hazard: the moment a salesperson pastes a credit application, a
driver's licence, or a deal jacket into a general-purpose AI assistant, customer information has left
the store and entered a service provider the dealer has not contracted, configured, assessed, or
documented. It is fast, it is useful, and it is exactly the exposure the amended rule was written to
address.
Primary source: FTC — Gramm-Leach-Bliley Act
The Red Flags Rule
Federal · 16 CFR Part 681 · FTC
Separately from Safeguards, covered creditors must maintain a written Identity Theft Prevention
Program: identify relevant red flags, detect them in day-to-day operations, respond appropriately,
and update the program periodically with senior-management or board oversight.
For a store, the red flags are operational rather than theoretical — a licence that does not match the
credit application, an address that appears across unrelated deals, a buyer who cannot answer
verification questions about their own file.
Architectural alignment: detection is a records problem before it is a policy
problem. When every document in a deal is filed, fingerprinted, and searchable inside the store,
the pattern across files is visible. When documents live in a shared drive, an email thread, and a
filing cabinet, it is not.
Primary source: FTC — Red Flags Rule
The deal jacket is the compliance artifact
Operational · Titles, tags, and the paper behind a sale
A dealership's regulatory exposure is not abstract; it is a stack of paper per vehicle. Bill of sale,
credit application, title work, odometer statement, buyer's guide, tag and transfer paperwork,
payoff documentation on a trade. Each has a deadline and a retention obligation, and each carries
nonpublic personal information.
What a sovereign deployment does with it
- Filed where the store is. Scans land on hardware in the building. Nothing is
uploaded to a third-party AI service to be read.
- Fingerprinted on arrival. Every document gets a SHA-256 content hash and an
intake id, so a file's integrity can be re-verified later rather than assumed.
- Read on the box. The bill of sale populates the VIN, sale date, and price;
every scan is classified and filed against its vehicle.
- Clocks that start themselves. A sold vehicle begins its title clock on filing,
and the tracker shows which paperwork is still missing per car.
Why this is a compliance posture and not a filing cabinet: the same act that
stores a document also proves it. Retrieval and verification are one operation, so a record produced
for an examiner carries the fingerprint it was sealed with.
What we do not claim
Read this part especially
Sovereignware does not make a dealership compliant. Compliance is a program — written, staffed,
trained, tested, and overseen — and no software supplies that. What the architecture supplies is
evidence: records that can be shown to be unaltered, a chain of custody for the
documents behind a deal, and a materially smaller service-provider surface to oversee, because
customer information is not being handed to a third-party AI vendor in the first place.
We have not been audited, accredited, or certified by the FTC or any standards body. A dealer's
obligations remain the dealer's, and whether this architecture suits a specific store is a decision
for that store's counsel and compliance officer.
The honest version of the pitch: we assist with evidence. We do not certify, and
we do not guarantee an outcome. Any vendor telling a dealer otherwise is selling something that will
not survive an examination.
Important — what this page is, and what it is not.
This page documents Sovereignware™'s architectural alignment with the regulations discussed
above. It is a posture statement, not a certification claim. We have not been
audited, accredited, or certified by any government agency, standards body, or third-party assessor
referenced here. Our customers' regulatory obligations are their own, and the appropriateness of
Sovereignware™ for any specific compliance use case must be evaluated by the customer's own counsel
and compliance officers.
Nothing on this page constitutes legal, regulatory, or compliance advice. Primary sources are linked
above and should be consulted directly.
Related: the full regulatory posture ·
law firms & privilege