LotRoster

LotRoster

Security

LotRoster is designed as a restricted business application with authenticated access, role-based permissions and defensive web controls.

Access controls

Operational pages require authenticated accounts created by an authorized administrator. Application permissions are limited by assigned role, and public visitors do not receive access to dealership operational records simply by reaching this website.

Web protections

Production traffic is served over HTTPS and the application uses restrictive browser security headers, including a Content Security Policy, anti-framing controls, MIME-sniffing protection, transport security and a restricted permissions policy.

Report a security issue

If you believe you have found a security issue affecting LotRoster, report it through the organization's established LotRoster administrator or security contact. Include the affected URL, a concise description and reproducible steps when safe to do so. Do not include passwords, authentication tokens, customer information or other sensitive dealership data in an initial report.

Automated security contact

Machine-readable disclosure guidance is published at /.well-known/security.txt on this domain.