Your group's own node. Not a row in someone else's table.
Most dealer software makes you a tenant in a shared system. That is fine until it isn't — because it means somebody else's bad day becomes yours, and you have no way to keep trading through it.
In June 2024, one vendor went down and took an industry with it.
A single ransomware attack on one dealer management provider took nearly 15,000 dealerships offline for close to three weeks. Deals were written on paper. Service lanes ran blind. The Anderson Economic Group put direct losses to affected dealers at around $1.02bn.
That was a US event and a UK group may not have felt it directly — but the architecture that caused it is the same one most of this industry still runs on. Not one of those businesses did anything wrong.
Isolated. Resilient. Networked.
Isolated
A dedicated database and network boundary for your group — not a shared table with a tenant column. One group's incident cannot reach another group's data, or another group's uptime.
Resilient
Your node holds a working copy of your operating data. If something upstream goes dark the service drive keeps writing repair orders, appointments keep booking, and it reconciles when the link returns.
Networked
Nodes exchange signal, never raw records. Fraud patterns and group benchmarks travel between them; the customer file never leaves the node it belongs to.
A dealer should never be told their business is shut because someone else's server is.
That is the whole argument, and it is an architectural choice — which means it has to be made before the software is written, not after the incident. It is also why your data is exportable on demand, with real tooling rather than a support ticket and a ninety-day wait. If the door is open, the only thing keeping you is whether the product works.
Ask us the hard questions.
We will walk your IT team through the architecture, the isolation boundary and the export path — and bring our control matrix with the open gaps still in it.
