Painter IQ holds the information that runs your business, customer names and addresses, estimates, invoices, payments, photos, and documents. This page lays out, in plain language, exactly how that data is protected, who processes it, and what we will and won't do with it. Questions about anything here? Email security@roof-metric.com.
Every record is scoped to your company at the database-query level. We run an automated cross-tenant probe suite that attempts to read and write other companies' data through every customer endpoint, every probe must fail before a release ships.
All traffic is encrypted in transit (TLS 1.2+, HTTPS-only with HSTS). Data is stored on managed cloud infrastructure with encryption at rest. Third-party integration credentials are additionally encrypted at the application layer before storage.
Passwords are stored only as one-way bcrypt hashes. Sessions use signed, expiring tokens. Team roles (owner / admin / member) gate sensitive actions, and site administration is fully separated from customer accounts.
Card and bank details never touch our servers. Payments run entirely on Stripe (a PCI DSS Level 1 provider) via Stripe Connect, money moves directly between your customer and your own Stripe account.
Destructive actions require explicit confirmation. Deleted customers are archived and restorable by your admin, and every plan includes full data export, your data is yours.
AI-connector activity, email sends, and administrative actions are logged. API access is rate-limited, and AI connections use scoped, revocable tokens you control per connection.
Painter IQ's content-understanding AI features (receipt scanning, document analysis, photo and damage analysis, estimate and template drafting, and the Connect AI assistant integrations) are powered by Anthropic's Claude commercial API. Under Anthropic's commercial terms, content submitted through the API is not used to train AI models.
Two narrow, specialized tasks that Claude does not perform use Replicate: converting a satellite image into a roof outline (image segmentation) and optional voice-note transcription. Replicate receives only satellite imagery and the photos or audio you provide for that task, never Google account data, customer or claim records, or payment information. We use no other AI providers, and we never sell or share your data for advertising or model training.
These are the service providers that may process data on our behalf, and what they process:
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Application & API hosting | All application traffic and hosted data |
| Managed PostgreSQL (provisioned via our hosting infrastructure) | Primary database | Account, customer, and project records (encrypted at rest) |
| Cloudflare R2 | File storage | Photos, documents, generated PDFs |
| Stripe | Payments & subscriptions | Payment details (never stored by us) |
| Anthropic (Claude API) | AI content analysis & drafting | Content you submit to AI features; not used for training |
| Replicate | Roof-image segmentation & voice transcription only | Satellite imagery and photos/audio you provide; no Google, customer, or payment data |
| Amazon SES | Transactional email delivery | Email addresses and message content you send |
| Optional Gmail / Calendar integrations | Only when you connect them; per the Limited Use disclosure above | |
| EagleView / ABC Supply | Optional per-contractor integrations | Order details you submit; connected under your own accounts |
We maintain a written information security program (WISP) covering access control, vendor management, data retention, and incident response, and we review it as the product evolves. Our SOC 2 readiness program is underway; security questionnaires from prospective customers are welcome at security@roof-metric.com.
Found a vulnerability? Please report it to security@roof-metric.com. We commit to acknowledging reports within two business days, and we won't pursue action against good-faith research that respects our users' data.