RafterCore holds your jobs, client records, documents, and payment activity. We take that seriously. Here's exactly how your data is handled โ and what you can always control.
All traffic between you and RafterCore is encrypted in transit with TLS/HTTPS. Data stored in our database is encrypted at rest by our infrastructure provider.
Card payments are processed entirely by Stripe, a PCI-DSS Level 1 provider. RafterCore never stores raw card numbers on its own servers.
RafterCore runs on SOC 2-compliant providers โ Netlify for delivery, Supabase/PostgreSQL for data, and Stripe for payments โ each independently audited.
Role-based permissions limit who on your team can see and do what. Privileged operations are authorized server-side, not in the browser.
Your data is backed up on an automated schedule so it can be restored in the event of a failure, with point-in-time recovery on our managed database.
We monitor for unusual activity and apply security patches to our platform and dependencies on an ongoing basis.
Found a security issue? We want to hear from you. Email security@raftercore.com with details and we'll respond promptly. Please give us reasonable time to investigate and fix before any public disclosure โ we appreciate the roofing and security communities helping us stay safe.
Evaluating RafterCore for your business and need to check a security or compliance box? We're happy to walk through it.
Book a call โ