Product security
Service Terminal Security
Direct answer
Service Terminal extends authorized existing workstation sessions through managed terminals designed for dealership service environments. Core operator sessions use outbound RDP to approved targets. The application does not persist RDP passwords, but limited operational state remains locally; optional services and dealership-side controls require explicit review.
Key takeaways
- The application does not persist RDP passwords.
- Username history, logs, network profiles, inventory, and optional device-service state can remain locally.
- Core operator sessions are outbound; optional administrative access is a separate dealership decision.
- Security updates, monitoring, lifecycle management, and support are managed components.
Public security model
The product acts as an access point to an employee's authorized existing workstation session. The terminal is not presented as a new dealership system of record and does not replace the applications employees use. Keeping the core systems unchanged limits the product's operational scope and supports reversibility. The public model should be understood as a starting point for technical review, not as a complete architecture or a certification.
Local data and credentials
Service Terminal does not become a dealership system of record, and the application does not persist the RDP password. It can retain username history, logs, network profiles, inventory and discovery state, device-lock state, and optional device-service state. Dealership IT should classify this operational state and confirm normal-use, support, replacement, retention, and removal controls.
Network direction and management
Core operator sessions use outbound RDP connections to approved targets, and optional device registration or telemetry can use outbound HTTPS. Optional administrative access is a separate deployment exception. Managed scope includes software and security updates, monitoring, lifecycle management, hardware, and support; responsibilities and evidence should be documented before deployment.
Security evaluation boundaries
Dealership IT should review identity and authorization behavior, proposed locations, network policy, physical access, logging and monitoring expectations, update and support processes, replacement, incident communication, and removal. This page deliberately avoids credentials, keys, sensitive network architecture, and implementation weaknesses. It also avoids claiming a security audit, certification, or vendor integration that has not been verified.
What to measure
Security questions resolved before deployment should be a closed list with named owners, not an open thread that deployment outruns. Managed device inventory, status, and update records are the continuing evidence that the approved configuration is still the deployed one. Support and escalation events reveal the operational reality of the estate, including exceptions that were granted informally. Schedule authorization, placement, replacement, and removal reviews on a defined cadence, because each is a control that decays quietly when it is performed only at installation.
- Security questions resolved before deployment
- Managed device inventory, status, and update records
- Support and escalation events
- Authorization, placement, replacement, and removal reviews
Relevant definitions
Dealership workflow infrastructure
Dealership workflow infrastructure is the combination of physical access points, software access, security controls, operational processes, and support systems that enables dealership employees to complete work across departments.
View glossary entryWorkflow latency
Workflow latency is the time between when work is completed, discovered, measured, diagnosed, or changed and when the next person in the repair process receives enough information to continue.
View glossary entryProduct relevance
How Service Terminal relates
Security is part of the Service Terminal product definition because the service department access layer must coexist with dealership systems and IT controls. The verified public characteristics allow an initial review while preserving sensitive implementation detail for an appropriate evaluation channel. The underlying dealership systems remain unchanged and the terminal can be removed without affecting operations.
Review the canonical product overview →Related questions
Does the terminal store customer data?
The terminal is not intended to replicate DMS, repair-order, or customer records, but it retains limited operational state such as username history, logs, network profiles, inventory, and optional device-service state. Dealership IT should classify and control that state.
Does normal operation require an inbound service?
The core operator workflow uses outbound client connections to approved targets. Optional administrative access can be configured separately and must be approved as a dealership exception.
What happens when a terminal is removed?
The terminal can be removed without affecting dealership systems or operations because it does not replace those systems. The managed removal and inventory procedure should still be followed.
Dealership evaluation
Test this in one representative workflow
Pick a repair-order transition where two measures can be observed under a stable definition: Security questions resolved before deployment and Managed device inventory, status, and update records. Involve the employees who do the work, plus dealership IT when authorized session access is in scope. Use the result to expand, relocate, narrow, or stop the test.