Security
Last updated
Written in plain English by the person who runs the service. It has not yet been independently reviewed by Australian legal counsel; the wording may change while the practices described remain those in place today.
What is in place to protect your account and your data, written for a roofer who wants the answer in plain English.
1. Sign-in
Sign-in and sessions are handled by Clerk. Your password is checked and stored by Clerk, not sent to or kept by Quick Roof. The sign-in methods on offer are the ones shown on the sign-in screen.
2. Accounting connections
Available accounting connections (Xero and QuickBooks Online) use OAuth 2. You authorise on the provider's own site and we receive a token, not your password. Tokens are encrypted before they are stored and are refreshed automatically in the background.
3. Data at rest
Service data is stored in managed PostgreSQL. Accounting OAuth tokens are encrypted by the application with AES-256-GCM before storage. Database access is limited to server-side application code and operational tooling.
4. Data in transit
Traffic between your browser and the service uses TLS. Certificates are managed and rotated by the hosting provider.
5. Payments
Stripe handles card details. Card numbers do not pass through or get stored on our systems.
6. Reporting a problem
Found something? Email security@quickroof.app. We will acknowledge the report, investigate it, and keep you updated. There is no paid bounty programme.
7. Where it runs
The app runs in Vercel's Sydney region and the database is in Sydney. Clerk, Stripe, Resend and Sentry process data in their own regions, listed below.
8. Sub-processors
The providers that handle data on our behalf, and what each one sees. Email security@quickroof.app for current provider details before procurement.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Clerk | Sign-in and sessions | Name, email and sign-in credentials | United States |
| Stripe | Billing | Card details, billing name and email, subscription status | United States |
| Vercel | Application hosting | Every request to the app passes through it | Sydney |
| Resend | Quote email delivery | Your customer's name and email, the quote link and PDF | United States |
| Sentry | Error monitoring | Error and performance data | United States |
| Managed Postgres provider | Data storage | Quotes, customers, cost library, account and connection records | Sydney |
9. Not yet
- No SOC 2 or ISO 27001 report.
- No uptime commitment.
- No public status page yet.
- No self-serve data export yet.
- Sign-in security features are the ones Clerk offers on the sign-in screen.