Encryption in transit
Traffic between your browser and the application is encrypted in transit using standard TLS.
Security and privacy controls are implemented across managed infrastructure, authenticated services, and tenant-scoped data access. Specific guarantees depend on your hosting and database providers.
Multiple layers of protection keep account and report data private across infrastructure, application, and storage.
Traffic between your browser and the application is encrypted in transit using standard TLS.
Workloads run on managed cloud infrastructure with isolated services, authenticated internal APIs, and continuous health monitoring.
Production data is stored in Supabase Postgres with row-level security policies and scoped service access controls.
Authentication and session handling run through Supabase Auth with tenant-scoped access patterns.
Privacy-first principles: collect only what is needed for the product, and provide controls to manage your data.
Operational monitoring, scheduled trust checks, and fail-secure API guardrails help detect and contain issues quickly.
A layered architecture protecting every stage from the edge to the database.
TLS termination and hosting-provider protections
Authentication, authorization, and server-side secrets
Database policies and least-privilege access
If you believe you found a security issue, use Contact support and label the message “Security disclosure.” Include the affected page, steps to reproduce, and likely impact. Do not send passwords, access tokens, customer data, or other secrets. We will review the report and use the contact details you provide for follow-up; this page does not promise a fixed response or resolution time.
Common questions about how MyRoofGenius protects your data.
Contact support to discuss requirements and request security documentation for your deployment.