Your data stays yours.
Always.
Roughin handles confidential business data — job margins, revenue, customer lists, and QuickBooks financials. We treat that responsibility the same way you'd expect a bonded subcontractor to treat your property.
Complete data isolation
Your company's data is physically separated from every other Roughin account at the database level using row-level security. No Roughin employee, other customer, or system process can query your data unless authorized.
Encrypted everywhere
All data is encrypted in transit over TLS 1.3 and at rest using AES-256. QuickBooks OAuth tokens are additionally encrypted with AES-256-GCM before being stored — we never store your QBO password.
Role-based access
Owners see margins. Office managers see jobs and invoices. Techs see quotes only — no cost data. Every action is logged to a tamper-evident audit trail so you always know who changed what and when.
Enterprise infrastructure
Roughin runs on Supabase (SOC 2 Type II certified) and Vercel (SOC 2 Type II certified). Automatic daily backups with point-in-time recovery. 99.9% uptime SLA on the underlying infrastructure.
Data protection
- AES-256-GCM encryption for all stored credentials and tokens
- TLS 1.3 for all data in transit — no unencrypted connections
- Row-level security (RLS) enforced at the database level, not just application code
- Company ID always sourced from server-side auth — never from request body
- Stripe handles all card data — Roughin never touches payment card numbers
Access & audit
- 5-level role system — owner, office manager, lead tech, field tech, super admin
- Every state-changing action (create, update, delete) written to an immutable audit log
- Technician accounts can quote jobs without ever seeing cost or margin data
- Session tokens expire and rotate on logout
- Rate limiting on all authentication endpoints to block brute-force attacks
QuickBooks integration
- OAuth 2.0 — we never see or store your QuickBooks password
- Access tokens are additional-layer encrypted with AES-256-GCM before storage
- You can revoke Roughin's QBO access at any time from your Intuit account
- Tokens are scoped to only what Roughin needs — no admin-level QBO permissions
Your rights & data
- We do not sell your data. Full stop.
- Your data is yours — export or request deletion at any time
- After cancellation, data is retained 90 days then permanently deleted
- Request immediate deletion by emailing support@getroughin.com
- We use only essential session cookies — no tracking or ad cookies
Built on enterprise-grade infrastructure
Supabase
SOC 2 Type II · Database & Auth
Vercel
SOC 2 Type II · Application hosting
Stripe
PCI-DSS Level 1 · Payments
Intuit QBO
OAuth 2.0 · Financial sync
Security questions?
If you've found a vulnerability or have security-related questions, email us directly. We respond within 24 hours.
security@getroughin.com