Authenticated use
Report generation, team management, billing, and report history require a signed-in user. New company owners complete an emailed verification-code step.
This page describes the protections currently implemented in RoofScore Pro. It does not claim certifications or guarantees the product has not earned.
Report generation, team management, billing, and report history require a signed-in user. New company owners complete an emailed verification-code step.
Database row-level security scopes report access to the signed-in user. Team and billing actions enforce owner or representative roles on the server.
Saved reports live in a private storage bucket and reopen through time-limited signed URLs rather than a permanent public report URL.
Production traffic uses HTTPS. The site sends HSTS, content-type protection, clickjacking protection, referrer and permissions policies, and a Content Security Policy that limits scripts, connections, frames, and form destinations.
Standard reports are retained for 90 days and a scheduled purge removes expired report files and records. Customers should save any report they need to retain longer.
RoofScore uses Supabase for authentication, database, storage, and server functions; Anthropic for AI-assisted photo and report processing; Resend for transactional email; Stripe for billing; and Netlify for website delivery. Payment card data is handled by Stripe, not stored by RoofScore.
Send the use case and the information you plan to process. We will answer with the current implementation, not a sales gloss.
Contact RoofScore