← Back to home

Trust Center

How HVAC IQ protect your business and your customers' data · Last updated: July 7, 2026

HVAC IQ holds the information that runs your business, customer names and addresses, estimates, invoices, payments, photos, and documents. This page lays out, in plain language, exactly how that data is protected, who processes it, and what we will and won't do with it. Questions about anything here? Email security@roof-metric.com.

Security posture at a glance

Tenant isolation

Every record is scoped to your company at the database-query level. We run an automated cross-tenant probe suite that attempts to read and write other companies' data through every customer endpoint, every probe must fail before a release ships.

Encryption

All traffic is encrypted in transit (TLS 1.2+, HTTPS-only with HSTS). Data is stored on managed cloud infrastructure with encryption at rest. Third-party integration credentials are additionally encrypted at the application layer before storage.

Authentication

Passwords are stored only as one-way bcrypt hashes. Sessions use signed, expiring tokens. Team roles (owner / admin / member) gate sensitive actions, and site administration is fully separated from customer accounts.

Payments

Card and bank details never touch our servers. Payments run entirely on Stripe (a PCI DSS Level 1 provider) via Stripe Connect, money moves directly between your customer and your own Stripe account.

Deletion safety

Destructive actions require explicit confirmation. Deleted customers are archived and restorable by your admin, and every plan includes full data export, your data is yours.

Auditing

AI-connector activity, email sends, and administrative actions are logged. API access is rate-limited, and AI connections use scoped, revocable tokens you control per connection.

How AI features handle your data

HVAC IQ's content-understanding AI features (receipt scanning, document analysis, photo and damage analysis, estimate and template drafting, and the Connect AI assistant integrations) are powered by Anthropic's Claude commercial API. Under Anthropic's commercial terms, content submitted through the API is not used to train AI models.

Two narrow, specialized tasks that Claude does not perform use Replicate: converting a satellite image into a roof outline (image segmentation) and optional voice-note transcription. Replicate receives only satellite imagery and the photos or audio you provide for that task, never Google account data, customer or claim records, or payment information. We use no other AI providers, and we never sell or share your data for advertising or model training.

Google API data & Limited Use disclosure

HVAC IQ's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Subprocessors

These are the service providers that may process data on our behalf, and what they process:

ProviderPurposeData involved
VercelApplication & API hostingAll application traffic and hosted data
Managed PostgreSQL (provisioned via our hosting infrastructure)Primary databaseAccount, customer, and project records (encrypted at rest)
Cloudflare R2File storagePhotos, documents, generated PDFs
StripePayments & subscriptionsPayment details (never stored by us)
Anthropic (Claude API)AI content analysis & draftingContent you submit to AI features; not used for training
ReplicateRoof-image segmentation & voice transcription onlySatellite imagery and photos/audio you provide; no Google, customer, or payment data
Amazon SESTransactional email deliveryEmail addresses and message content you send
GoogleOptional Gmail / Calendar integrationsOnly when you connect them; per the Limited Use disclosure above
EagleView / ABC SupplyOptional per-contractor integrationsOrder details you submit; connected under your own accounts

Your data rights

Our program

We maintain a written information security program (WISP) covering access control, vendor management, data retention, and incident response, and we review it as the product evolves. Our SOC 2 readiness program is underway; security questionnaires from prospective customers are welcome at security@roof-metric.com.

Responsible disclosure

Found a vulnerability? Please report it to security@roof-metric.com. We commit to acknowledging reports within two business days, and we won't pursue action against good-faith research that respects our users' data.