LotRoster
Security
LotRoster is designed as a restricted business application with authenticated access, role-based permissions and defensive web controls.
Access controls
Operational pages require authenticated accounts created by an authorized administrator. Application permissions are limited by assigned role, and public visitors do not receive access to dealership operational records simply by reaching this website.
Web protections
Production traffic is served over HTTPS and the application uses restrictive browser security headers, including a Content Security Policy, anti-framing controls, MIME-sniffing protection, transport security and a restricted permissions policy.
Report a security issue
If you believe you have found a security issue affecting LotRoster, report it through the organization's established LotRoster administrator or security contact. Include the affected URL, a concise description and reproducible steps when safe to do so. Do not include passwords, authentication tokens, customer information or other sensitive dealership data in an initial report.
Automated security contact
Machine-readable disclosure guidance is published at /.well-known/security.txt on this domain.