DP360 has been around since 2014 with a wide partner footprint. The marketing covers a lot of ground; the shipped product covers less of it. The categories below are where the architecture, the AI depth, the security posture, and the scale of independently-compiled data underneath DealerCRM put it a generation ahead — and it shows the moment a customer talks to your dealership.
DP360 was built in 2014 on a traditional monolithic stack. DealerCRM was built on the modern serverless edge — every feature scales to thousands of dealers without re-platforming, and every secret, session, and audit row meets enterprise security review out of the box.
Enterprise dealer groups require substantiated controls from any vendor touching customer PII. We provide direct evidence for the controls we can substantiate — encrypted credentials per tenant, HMAC-signed webhooks, constant-time comparisons, signed identity tokens with TTL, complete changelog audit trail. It's the difference between "we're trying to sell into the top 50 groups" and "we already cleared procurement."
This isn't a vanity choice — compliance and AI almost require it. The moment a customer's call gets handed off to a third-party recorder, or a text gets routed through a partner SMS gateway, or an email runs through a third-party deliverability provider, you lose the ability to control the data flow, the consent record, and the AI context window. You also add another vendor to your SOC 2 report and another invoice to your stack.
Carrier-grade phone, voicemail, recording, transcription, and AI voice all run on our platform. The audio stream never leaves our edge before AI sees it. DP360 routes calls and AI recap through a third-party calling vendor.
Inbound and outbound SMS/MMS, opt-in flow, STOP detection, freeform-language opt-out classifier, autonomous AI drafts — all on our infrastructure. Every message is a row we own with a complete consent audit trail.
Send, receive, parse, classify, opt-out. Every inbound email is processed by our AI for intent before it ever hits the rep's inbox. CAN-SPAM audit trail is first-party data, not a partner's API.
For compliance: TCPA, CAN-SPAM, and SOC 2 all require auditable consent and an end-to-end data trail. Every third party in the path is another link that has to be in your audit, another DPA to renew, another vendor to drop into your incident response, and another reason an enterprise procurement team can say no.
For AI: the AI is only as good as the context it can see. When calls, texts, emails, and Facebook / Instagram / WhatsApp messages all run through our own pipes, the AI has the full conversation history, the full consent record, and the full customer state to reason from — across channels, in real time. When those flows are siloed inside three different partner platforms, the AI sees fragments. That's why DP360's AI SMS layer underdelivers in the field, and why their voice "AI recap" is a one-line summary instead of a contextual continuation of an ongoing conversation.
A customer texts a trade-in photo, snaps a window sticker, sends a walkaround video, or chats on your website before they ever give a name. On most CRMs that's a dead-end attachment nobody opens — and anonymous web traffic stays invisible. DealerCRM reads it all and ties it to the right customer, across every channel, even before they identify themselves.
The newest layer, live in production on the same platform — still one login, one customer record, one vendor.
The stacks below are in production today. These landed after them, on the same platform — still one login, one customer record, one vendor.
The eight-tool spring stack below was only the start. The summer releases below are built into the same platform — not bolted on or bought.
No middleware, no third-party SMS or voice vendors stitched together — these eight shipped on one in-house stack this spring, so OliviaAI sees the whole conversation.
DP360 markets AI Email + AI SMS as separate paid tiers; the SMS layer in particular has known quality issues in the field. Their pipeline-scoring "AI Data Analyst" is announced for late 2026 — not yet shipping.
DP360 has no native desking. Deals are pipeline records; payments, tax, lender programs, and credit all live in third-party tools — Dealertrack, 700Credit, Accu-Trade — that the rep has to leave the CRM to use. AutoPencil is built into the platform — and every other surface (text, email, voice, eBrochure) can read from it and write to it in real time.
DP360 sells AI as Essential / Advanced / Premium tiers bolted onto an existing CRM. Same data, same workflow, just a paid feature flag turning on email → SMS → "AI Data Analyst" (which is announced for late 2026 and not yet shipping). Our AI is foundational — every surface shares one model registry, one customer context, one tool catalog.
DP360 receives DMS feeds. We built — and continuously enrich — the catalog itself.
DP360 consumes marketplaces only as inbound lead sources. We track every listing — pricing, lifecycle, days-on-market.
DP360 has no customer-facing portal product. Reviews flag this as a gap.
DP360 records calls. They have nothing else productized for opt-in/opt-out. We treat compliance as a first-class feature.
DP360 click-to-call routes through Car Wars for recording and AI recap. Ours is native — no third-party tax.
Every finding below is from a strictly public source — DNS records, certificate transparency logs, their own JavaScript bundles served to every browser, public app store metadata, public press releases, and public regulator-style filings. No login attempts, no scanning, no probing, no exploitation, no leaks. This is the receipts.
Their production application loads Angular 10.2.5 (end-of-life since May 2022), CKEditor 4.16.0 (end-of-life June 2023), and Revolution Slider 5.4.8.3 — a 2018 build of the most-attacked WordPress plugin in history, with multiple known unpatched XSS vulnerabilities in the 5.x line.
Evidence: framework version strings inside their own minified production bundles, plugin paths exposed in their marketing-site HTML.
Their public integration API documentation generator timestamp is 2019-07-29T12:22:26Z. That's six years frozen. The total public API surface is 14 endpoints — Lead, Contact, Inventory CRUD only. No appointments, no SMS, no voice, no email, no deals, no service, no documents.
Evidence: their published api_project.json generator timestamp, and a full enumeration of api_data.json.
Their iOS app is on version 1.5.4 with active updates (last update April 2026). Their Android app is on version 0.8 — still pre-1.0 — last updated March 2025. A year-plus of zero Android maintenance. Any dealer rep with an Android phone is on a stale build.
Evidence: Apple iTunes lookup API for iOS; APKCombo schema.org metadata for Android.
Their privacy policy was last updated August 4, 2020. The contact email listed for privacy
requests is privacy@dp360rm.com — note the typo, missing "c". That domain doesn't resolve. Any GDPR
or CCPA request a customer sent to that address would bounce. Annual privacy review is a baseline expectation under both regulations.
Evidence: their published privacy policy HTML; DNS A/MX lookup of dp360rm.com.
Modern enterprise security baseline (RFC 9116) expects every vendor to publish a /.well-known/security.txt
file naming a contact for vulnerability disclosure. They have one on none of their domains.
A security researcher who finds a vulnerability has no clean path to report it.
Evidence: HEAD requests to every standard security-disclosure path on every DP360-controlled domain.
DP360's published partner list includes CDK Global, Motility Software Solutions, and 700Credit. All three suffered major security incidents in a 17-month window:
DP360 itself was not breached in any of these incidents. But every dealer on DP360 routes data through these partners, and every partner is part of the SOC 2 sub-processor chain a customer's procurement team has to evaluate.
Evidence: BleepingComputer, TechRadar, CBT News reporting; DP360's own published partner pages.
Their production JavaScript bundle imports the Twilio Voice JS SDK and Twilio Programmable Messaging directly. Their public press releases announce a Car Wars integration for call recording and AI recap. So a voice call on DP360 is: customer ↔ Twilio ↔ Car Wars ↔ DP360 ↔ rep. Two third-party vendors in the data path. Two SOC 2 sub-processors. Two DPAs.
Evidence: Twilio SDK strings (twilio-js-sdk, twilio/voice-sdk, twilioLeadMessage) in their main.js bundle; Car Wars co-branded press release on their site.
Their production app loads FullStory — a session-replay tool that captures every click, scroll, and keystroke a user makes inside the application. That includes everything a rep types into a customer record: PII, credit info, deal numbers, internal notes. Every keystroke is sent to a third party for storage and later replay. A real procurement objection in 2026 enterprise dealer-group deals.
Evidence: fullstory identifier and module imports in their main.js bundle.
Visible in their DNS, headers, and bundles: Twilio, Stripe, FullStory, Segment, Google Analytics, HubSpot, Emma, Zoho, Mimecast, Microsoft 365, Google Workspace, Atlassian, Zendesk, OpenAI, Anthropic, AWS, WP Engine, Cloudflare, CKEditor's CDN, WebSpellChecker, NCompassTrac, Car Wars. Every one is a SOC 2 sub-processor a customer's audit team has to evaluate, a DPA to maintain, and a separate breach surface DP360 doesn't control.
Evidence: DNS TXT records, HTTP headers, JavaScript bundle imports, third-party CDN URLs in HTML.
Their development API environment, dev-api.dp360crm.com, resolves publicly to an AWS load balancer in
us-east-2. Even when firewalled, a publicly-named dev environment is a recon advantage for attackers and a standard SOC 2 finding
worth raising. Production isolation discipline says dev surfaces don't get DNS in the public zone.
Evidence: dig dev-api.dp360crm.com; their own published api_project.json lists this URL as the dev environment.
Public third-party review sites (SourceForge, Capterra) carry a polarized picture. The negatives, in customers' own words:
Evidence: SourceForge and Capterra public review aggregators.
Every claim above is from a publicly-served artifact: their own DNS records, their own JavaScript bundles, their own API documentation, their own privacy policy, their own published partner list, public app store metadata, public press releases, public certificate transparency logs, and public-record breach notifications from major outlets (BleepingComputer, TechRadar, CBT News). No login was attempted. No vulnerability was exploited. No insider information was used. We're happy to walk any prospect's procurement team through the receipts on a call.
AI, desking, catalogs, marketplace intelligence, customer-facing surfaces, and enterprise compliance — every category that decides the next five years of dealership software, we already shipped and the field has confirmed it works.