Device & network security
Reference information for a vendor security review of the PrintSent appliance: what it listens on, what it connects to, how remote support access works, what it holds, who processes your data, and who owns the hardware.
For document handling, retention, and FTC Safeguards, see security & compliance.
Summary
Each line is expanded further down the page.
- What it is
- A single-function network appliance. It accepts print jobs on the IP addresses you assign it, uploads them to PrintSent, and does nothing else.
- Where it sits
- On your Dealertrack VPN-connected network, next to your other Dealertrack printers — it imitates a printer so Dealertrack can send jobs to it. It sits behind your existing edge firewall and NAT, and accepts no inbound connections from the public internet.
- Ports open to your network
- TCP 9100 for print data, and TCP 80 for the printer identity page Dealertrack's device setup requires, which also serves a read-only status page. Nothing on the device is configurable over the network; all configuration is done in your PrintSent account. No other ports are reachable from your network.
- Inbound from the internet
- None. No port forwarding, NAT rule, or firewall exception is required, and none is requested.
- Outbound connections
- Encrypted (TLS) to PrintSent. The device uploads captured jobs and periodically checks in for its configuration and updates.
- Remote support access
- Yes, over an outbound-initiated, MFA-protected remote management service, used for updates and troubleshooting. No inbound rule on your edge firewall.
- Data held on the device
- A local spool queue. Jobs are written to disk, uploaded, and removed. If the internet connection is unavailable, jobs queue on the device and upload when it returns. There is no permanent document archive on the unit.
- Software on your machines
- None. No agents, no print drivers, no workstation installs, no domain join, no administrative credentials.
- DMS access
- None beyond the print jobs sent to it. It holds no Dealertrack credentials.
- Traffic it initiates on your LAN
- Only if you configure a Forward to Printer action, in which case it sends print data to the printer IP you specify. Otherwise it initiates no traffic to other hosts on your network.
- Network services
- None. It does not serve DHCP or DNS, and does not route traffic.
- Patching
- Ours. Firmware and software updates are applied by us while your subscription is active.
- Ownership
- The device is sold to you. Title transfers as stated in your order form, and it is yours to keep. There is nothing to return if you cancel.
What the appliance does and doesn't do
It sits inside your network behind your edge firewall, accepts print jobs on the IPs you assign it, and uploads them over an encrypted outbound connection.
It listens for print jobs
TCP 9100 accepts print data. TCP 80 serves the printer identity page Dealertrack's device setup requires, plus a read-only status page. Nothing else on the unit is reachable from your network.
It does not scan or enumerate
The device does not sweep for hosts, discover devices, probe shares, or contact anything it was not explicitly configured to reach.
Outbound-only to PrintSent
It opens its own encrypted connection out. Nothing inbound from the internet is required, so no ports are forwarded and nothing is published to the internet.
No agents, no domain join
Nothing is installed on workstations or servers. The device is not domain-joined, holds no directory credentials, and requires no administrative account on your network.
Spool, upload, clear
Jobs are written to a local spool queue, uploaded, and removed. If connectivity drops, jobs queue on the device and upload when it returns. The unit is not a document archive.
No footprint on anything else
It uses the IPs you assign and minimal bandwidth. It does not serve DHCP or DNS, and does not route traffic. Unplug it and nothing else on your network changes.
What it doesn't do
- No inbound access from the public internet
- No settings, shell, or admin interface exposed on the device
- No software or agents on workstations or servers
- No domain join and no administrative credentials
- No access to your DMS beyond the jobs printed to it
- No network discovery, scanning, or enumeration
- No DHCP, DNS, or routing services
Forward to Printer: the one action that sends traffic on your LAN
PrintSent supports an optional Forward to Printer action, configured per printer and document type. When enabled, the device sends the print data on to a printer IP address you specify. This is used when you want an emailed PDF and a paper copy, or one job to reach more than one printer.
This is the only case in which the appliance initiates traffic to another host on your network. It is not enabled by default. You choose the destination IPs, and the action can be changed, disabled, or removed at any time from your account. With no forwarding action configured, the device initiates no traffic to other hosts on your LAN.
How our access to the device works
We access the device remotely to apply updates and troubleshoot. Your service agreement authorizes this for the term of your subscription, and it ends when the subscription ends.
That access runs over an outbound-initiated remote management service, so no inbound rule or port forward is required on your edge firewall. The account controlling it requires multi-factor authentication and is limited to the staff who provide support. It is scoped to the appliance, not to your wider network.
Routine operation does not involve a person connected to the device. It captures jobs, uploads them over its outbound encrypted connection, and periodically checks in for its configuration and updates.
This page describes controls rather than implementation. Specific tooling, protocols, and device internals are not published here; we provide them in a completed security questionnaire or directly to your IT team on request.
What leaves your network, and who processes it
The FTC Safeguards Rule makes dealerships responsible for overseeing the service providers that handle customer information. Each vendor below links to its own published security documentation.
What leaves your network
The print jobs sent to the device and the PDFs generated from them, over an encrypted connection. They are held in encrypted-at-rest storage on Vercel for 12 hours, then deleted automatically.
PrintSent doesn't read, parse, or store the content of your printed documents — it applies your form template and delivers the PDF.1
1 Two narrow exceptions: it decodes the reference barcode your printer already embeds in the job to identify the document, and the optional Statement Sender reads the account number on statements you upload so it can route each one to the right recipient.
Print-job data stays inside PrintSent to run the service — it is never sent to AI tools or other third-party services, and your documents and any extracted text are never used to train AI or machine-learning models.
What persists is non-content metadata: document type, page count, delivery status. PrintSent is not a document archive, and Dealertrack remains your system of record. All PrintSent hosting and document storage is in the United States.
Vercel
Web application hosting and encrypted document storage (United States)
SOC 2 Type II (Security, Confidentiality, Availability) · ISO 27001:2022
Their security documentationRender
Document rendering service
SOC 2 Type 2 · ISO 27001 · HIPAA · GDPR DPA · EU-US Data Privacy Framework
Their security documentationSMTP2GO
Email delivery
ISO 27001 and ISO 9001 certified. Its US data centers (Chicago, Washington DC) are SOC 2 Type 2, ISO 27001, and PCI DSS certified. TLS in transit, AES-256 at rest.
Their security documentationEach subprocessor is engaged under a data processing agreement. The certifications above are the vendors' own, stated as they publish them, and are not claimed as PrintSent's. See our posture below.
Certifications and controls
PrintSent does not currently hold its own SOC 2 attestation. We build on infrastructure providers that do. Their certifications are theirs, not ours, and we do not present them as covering PrintSent.
The controls we operate:
- Least-privilege access: production access is limited to the people who require it to operate the service
- MFA required on administrative access and on remote support access to the device
- Encryption in transit and at rest for every document
- Short retention: documents are deleted automatically within 12 hours
- No third-party AI: print-job data stays inside PrintSent — never sent to AI tools or other outside services, and never used to train AI or machine-learning models
- No customer personal information in email subject lines or body text
- US hosting: the application and the encrypted document storage both run in the United States (Vercel)
- Named subprocessors, each under a data processing agreement
- Breach notification to affected dealerships without unreasonable delay
PrintSent was built by people who have run security controls inside dealerships, banking, and HIPAA-regulated organizations. More about who builds it.
PrintSent supports your information security program; it does not replace it. Your compliance team owns the service-provider determination.
Deployment, patching, and end of service
It arrives pre-configured
The device is staged before it ships. Your team connects ethernet and power and assigns its IP addresses. There is no build, image, or hardening step for you to own.
We keep it current
Firmware and software updates are applied by us while your subscription is active. There is no patch cycle for your team to manage.
You own the hardware
The device is sold to you, not leased. Title transfers as stated in your order form and the unit is yours to keep. The software on it is licensed for the term of your subscription, not sold.
If you cancel
Remote support and software updates stop, and the device stops processing jobs to PrintSent. You keep the physical unit; because it is no longer maintained, we recommend decommissioning it from your network. There is nothing to ship back.
Common review questions
Send us your security questionnaire
Email it over and we'll complete it. We'll also sign a data processing agreement and walk your IT team or MSP through the deployment before installation.
What to send
- Your vendor security questionnaire, in whatever format your program uses
- A data processing agreement or vendor agreement for us to review and sign
- Specific questions this page doesn't answer, including implementation detail we don't publish here
- A request for a call with your IT team or MSP before installation
Prefer to talk it through? Call (830) 420-6445.