Security & data handling

Clear controls, short retention, and no mystery claims.

This page describes the protections currently implemented in RoofScore Pro. It does not claim certifications or guarantees the product has not earned.

Current controls

Protection at the account, company, and report level.

01 / ACCESS

Authenticated use

Report generation, team management, billing, and report history require a signed-in user. New company owners complete an emailed verification-code step.

02 / ISOLATION

Private report rows

Database row-level security scopes report access to the signed-in user. Team and billing actions enforce owner or representative roles on the server.

03 / LINKS

Short-lived report access

Saved reports live in a private storage bucket and reopen through time-limited signed URLs rather than a permanent public report URL.

Transport and browser policy

Production traffic uses HTTPS. The site sends HSTS, content-type protection, clickjacking protection, referrer and permissions policies, and a Content Security Policy that limits scripts, connections, frames, and form destinations.

Retention

Standard reports are retained for 90 days and a scheduled purge removes expired report files and records. Customers should save any report they need to retain longer.

Service providers

RoofScore uses Supabase for authentication, database, storage, and server functions; Anthropic for AI-assisted photo and report processing; Resend for transactional email; Stripe for billing; and Netlify for website delivery. Payment card data is handled by Stripe, not stored by RoofScore.

Customer responsibilities

Security is also operational.

  • Use a unique password and protect the email account used for verification and recovery.
  • Share only inspection photos and customer details you are authorized to process.
  • Review generated content before presenting it to a homeowner or relying on it operationally.
  • Remove former representatives promptly and do not share owner credentials between users.
  • Report suspected unauthorized access through the contact page.
Not claimed: RoofScore Pro does not currently claim SOC 2, ISO 27001, HIPAA, PCI merchant certification, or independent penetration-test certification. Stripe handles card entry on its hosted checkout.

Questions about a specific control?

Send the use case and the information you plan to process. We will answer with the current implementation, not a sales gloss.

Contact RoofScore