Security

Your data stays yours.
Always.

Roughin handles confidential business data — job margins, revenue, customer lists, and QuickBooks financials. We treat that responsibility the same way you'd expect a bonded subcontractor to treat your property.

Complete data isolation

Your company's data is physically separated from every other Roughin account at the database level using row-level security. No Roughin employee, other customer, or system process can query your data unless authorized.

Encrypted everywhere

All data is encrypted in transit over TLS 1.3 and at rest using AES-256. QuickBooks OAuth tokens are additionally encrypted with AES-256-GCM before being stored — we never store your QBO password.

Role-based access

Owners see margins. Office managers see jobs and invoices. Techs see quotes only — no cost data. Every action is logged to a tamper-evident audit trail so you always know who changed what and when.

Enterprise infrastructure

Roughin runs on Supabase (SOC 2 Type II certified) and Vercel (SOC 2 Type II certified). Automatic daily backups with point-in-time recovery. 99.9% uptime SLA on the underlying infrastructure.

Data protection

  • AES-256-GCM encryption for all stored credentials and tokens
  • TLS 1.3 for all data in transit — no unencrypted connections
  • Row-level security (RLS) enforced at the database level, not just application code
  • Company ID always sourced from server-side auth — never from request body
  • Stripe handles all card data — Roughin never touches payment card numbers

Access & audit

  • 5-level role system — owner, office manager, lead tech, field tech, super admin
  • Every state-changing action (create, update, delete) written to an immutable audit log
  • Technician accounts can quote jobs without ever seeing cost or margin data
  • Session tokens expire and rotate on logout
  • Rate limiting on all authentication endpoints to block brute-force attacks

QuickBooks integration

  • OAuth 2.0 — we never see or store your QuickBooks password
  • Access tokens are additional-layer encrypted with AES-256-GCM before storage
  • You can revoke Roughin's QBO access at any time from your Intuit account
  • Tokens are scoped to only what Roughin needs — no admin-level QBO permissions

Your rights & data

  • We do not sell your data. Full stop.
  • Your data is yours — export or request deletion at any time
  • After cancellation, data is retained 90 days then permanently deleted
  • Request immediate deletion by emailing support@getroughin.com
  • We use only essential session cookies — no tracking or ad cookies

Built on enterprise-grade infrastructure

Supabase

SOC 2 Type II · Database & Auth

Vercel

SOC 2 Type II · Application hosting

Stripe

PCI-DSS Level 1 · Payments

Intuit QBO

OAuth 2.0 · Financial sync

Security questions?

If you've found a vulnerability or have security-related questions, email us directly. We respond within 24 hours.

security@getroughin.com