Regulatory Note: OCR fines and state AG investigations can follow a single patient complaint or breach notification. Compliance is not optional.
The FTC Safeguards Rule deadline has passed — every dealership handling consumer financial data needs a compliant WISP in place now. Book a free assessment and find out where your dealership stands on both compliance and DMS uptime protection.
No disruption. No lengthy onboarding. A fast, smooth transition to a partner that has your back from day one.
A Gradius engineer audits your dealership's IT environment — DMS infrastructure and connectivity, FTC Safeguards compliance posture, F&I workstation security, network segmentation, backup integrity, and service department IT — and gives you an honest picture of where your dealership stands. At no cost, no obligation.
A flat-rate plan built specifically for your dealership — sized to your rooftop count, your DMS platform, your F&I volume, and your compliance requirements. For dealer groups, we scope across all rooftops and deliver a unified program that standardizes compliance and security across the group.
Our engineers deploy, configure, and meet your team — typically live within 1–2 weeks without disrupting daily operations.
24/7 DMS and infrastructure monitoring, proactive support calibrated to dealership operating hours, quarterly compliance reviews to keep the WISP current, and planning for new rooftop additions, DMS upgrades, and technology lifecycle decisions before they become operational crises.
Our IT services for auto dealerships include DMS uptime monitoring and support (CDK, Reynolds & Reynolds, DealerSocket, Dealertrack, and others), FTC Safeguards Rule WISP development and maintenance, F&I cybersecurity and customer data protection, service department and parts IT support, network segmentation between dealership departments, 24/7 NOC and SOC monitoring, endpoint security and EDR, backup and disaster recovery, and on-site support across NJ, NY & CT — all under a flat monthly rate per rooftop with no per-ticket charges or emergency billing when the DMS needs urgent attention.
The FTC Safeguards Rule requires auto dealerships that handle consumer financial information — credit applications, financing agreements, insurance, and related data — to implement and maintain a Written Information Security Program (WISP). The WISP must include a designated information security coordinator, a risk assessment, specific technical safeguards (encryption, multi-factor authentication, access controls, patch management, incident response procedures), employee training, and annual review. The rule applies to virtually every new and used car dealership in the country. Gradius builds your compliant WISP, implements the required technical controls, provides supporting documentation, and maintains the program continuously — so your dealership is FTC-compliant and ready for any franchise or regulatory review.
Yes. We support the major DMS platforms used by dealerships in NJ, NY & CT — including CDK Global (CDK Drive), Reynolds & Reynolds (ERA-IGNITE and Reynolds DMS), DealerSocket DMS, Dealertrack DMS, Auto/Mate, and others. We understand how each platform's connectivity requirements interact with dealership network infrastructure, what dependencies to monitor, and how to troubleshoot DMS-related issues efficiently without waiting for the DMS vendor's support queue. We also coordinate with DMS vendor support when escalation is needed, acting as your technical advocate rather than leaving your staff to navigate it alone.
F&I customer data protection starts with workstation-level controls — encrypting drives on F&I desktops and laptops, restricting which users can access F&I applications and customer records, implementing DLP policies that monitor for unusual copying or printing of sensitive records, and ensuring F&I workstations are on a network segment separate from the general dealership network. We also implement MFA for any cloud-based F&I tools, monitor F&I workstations with endpoint detection and response, and include F&I-specific incident response procedures in the dealership's WISP documentation.
Yes. Multi-rooftop dealer groups are one of our most common dealership engagements. We standardize IT infrastructure, FTC Safeguards compliance, network security, and DMS monitoring across every rooftop under one program — so the group has a consistent security posture and compliance standing at every location, not a patchwork of different providers and different WISP documents. Flat-rate pricing per rooftop scales cleanly as the group adds new stores, and one account team manages the relationship across the entire group.
No long-term lock-ins. We offer month-to-month and annual agreements — your choice. Dealerships stay with Gradius because the DMS stays up, the WISP stays current, F&I data stays protected, and IT stops being a source of operational or compliance risk. We earn the renewal every month through performance.
Gradius IT Solutions serves businesses throughout the Tri-State area. Headquartered in Hackensack, NJ with coverage across Bergen, Hudson, Passaic, Essex, Union, Morris, Middlesex, Somerset, Sussex, Westchester, Rockland, and Fairfield Counties.