DealSmart AI
How It WorksWhy MaxFAQTeamSee Max

Compliance & Security

Enterprise-grade.
Fully transparent.

Regulatory rigor. Full audit trails. No black boxes.

TCPA

Compliant

Compliant with the Telephone Consumer Protection Act at federal and state levels. Consent collection, opt-out management, calling hour restrictions, and do-not-call list scrubbing handled automatically.

Formal legal opinion letter on file from a nationally recognized telecom compliance firm. Independent validation, not a self-assessment.

SOC 2 Type II

Q1 2026

Certification in progress covering security, availability, processing integrity, confidentiality, and privacy.

Independent third-party audit of access controls, encryption protocols, incident response, and operational procedures.

CCPA & State Privacy

Compliant

Compliant with California Consumer Privacy Act and state privacy regulations in Virginia, Colorado, Connecticut, and Utah.

Full support for consumer access, correction, deletion, and opt-out requests. We do not sell personal information.

GDPR

Supported

Supports EU data protection requirements including lawful basis for processing, data portability, and right to erasure.

For dealer groups with international operations or customers.

Data Architecture

Enterprise-grade

AES-256 encryption at rest. TLS 1.3 in transit. End-to-end protection across all data flows.

Logical isolation per dealership. No cross-account data access. Distributed infrastructure with automated failover and disaster recovery.

Access Controls

Full Audit Trail

Role-based permissions by user, role, rooftop, and function. Granular control over who sees what.

Full audit trail on every action, login, and configuration change. No silent access. No exceptions.

AI Governance

Enforced

Pricing limits, discount authority, and terms enforced at the system level. Cannot be overridden by the AI.

Every AI decision logged and traceable. Configurable escalation rules. Ongoing bias monitoring. No black-box behavior.

OEM Compliance

Fortellis Certified

Architected to meet OEM data handling and integration requirements.

Compatible with existing franchise agreements and platform guidelines.

Incident Response

Documented

Documented incident response procedures with defined escalation paths.

Notification protocols aligned with regulatory and contractual obligations.

Summary

RequirementStatus
TCPA (Federal & State)Compliant, legal opinion on file
SOC 2 Type IIIn progress, Q1 2026
CCPACompliant
GDPRSupported
Data EncryptionAES-256 / TLS 1.3
Data IsolationLogical separation by account
Role-Based AccessFull audit trail
AI GuardrailsEnforced, auditable
Voice RecordingEncrypted, consent-verified
FortellisCertified

Dedicated compliance and security personnel available for enterprise reviews.

By requesting a demo, you consent to receive communications from DealSmart AI.

PrivacyTermsCompliance