Ship secure contractor software.

TLS 1.3 in transit, AES-256 at rest, and row-level isolation per company, protecting your customer data, quote history, payment records, and crew timesheets. And a privacy stance you can show a homeowner without hedging.

Running on the same stack as
VercelSupabaseAWS us-eastStripeSentryUpstash
01Security benchmark

What's default here is optional somewhere else.

Four controls most field-service tools leave to chance.

Control
RevCore Pro
Typical tool
TLS handshake
1.3, no fallback
Mixed, 1.2 fallback common
At-rest encryption
AES-256
Varies by vendor
Row-level isolation
Enforced at the database
App-layer only
Continuous GPS on crew
Never
Default-on in many tools
0%

of traffic on TLS 1.3

256-bit

AES at rest

0

breaches to date

0h

breach notification SLA

02Controls

Secure by default. Compliant from day one.

Every control here is enforced on every account. Nothing is a premium add-on, and nothing is configuration you have to remember to turn on.

SOC 2 Type II

In progress

Type II audit preparation underway, with controls mapped to the Trust Services Criteria.

TLS 1.3

No fallback

All traffic encrypted in transit on the latest protocol, with no fallback to older versions.

AES-256 at rest

Every row

Every row, attachment, and backup is encrypted at rest in a US-hosted region.

Row-level security

Database layer

Enforced at the database. A rep physically cannot read another company's data.

Scoped access

4 roles

Owner, Manager, Rep, and Tech roles, each limited to the minimum surface they need.

Hosted in the US

AWS us-east

Vercel edge plus Supabase on AWS us-east. No data transferred abroad without your direction.

03Architecture

How your data actually flows.

The same request path handles a quote lookup, a payment, and a crew clock-in. No secret back-channels, no customer tier that unlocks weaker defaults.

Browser
TLS 1.3
Vercel Edge
rate-limited
Next.js Server
auth, RBAC
Supabase, RLS
AES-256 at rest
Cross-region backup
AWS us-west
In flight

TLS 1.3, HSTS preload, no TLS 1.2 fallback.

In process

Row-level security and service-role isolation on every table.

At rest

AES-256 on every row and attachment, with cross-region backups.

04Principles

Three pillars. Built in, not bolted on.

01

Encryption, end to end

Every byte is encrypted in flight and at rest. Backups are stored in a geographically isolated region and verified with automated restoration tests.

  • TLS 1.3 with HSTS preload
  • AES-256 at rest on every row
  • Cross-region backups, restore-tested weekly
02

Access, always scoped

Row-level security on every table. Service-role keys are never exposed to the client. Every privileged operation happens server-side and is logged.

  • Supabase RLS, not app-layer checks
  • Service-role keys held server-side only
  • Four canonical roles, nothing ad-hoc
03

Detection, on a loud schedule

Error monitoring with PII scrubbed before send. Rate-limiting on every public endpoint. Dependencies reviewed weekly, with an on-call runbook already written.

  • Sentry with PII scrubbing
  • Rate-limited public endpoints
  • Weekly dependency review cycle
05How we ship

Secure SDLC. Boring on purpose.

Security is not a quarterly review deck. It is enforced in the commit, the pull request, and the deploy pipeline, so the engineers who built the product cannot ship something unsafe by accident.

2
reviewers required

Every change to auth, billing, or access control needs a second set of eyes before merge.

Weekly
dependency review

Automated audit plus a human sweep every week. Critical CVEs patched within 72 hours.

100%
PRs behind CI

Typecheck, lint, and tests all green before a deploy is allowed.

24h
breach notification

Material incidents disclosed to affected customers within a calendar day, in plain English.

06Privacy stance

Security is also what we don't collect.

No continuous GPS, no fleet telemetry, no just-in-case data. On Pro and Scale we capture location server-side at exactly three crew events to prove presence. Outside of those, we don't know where your crew is, and we are not asking.

Captured
  • Clock-in. One location fix, verified against the job address.
  • Clock-out. One fix, when the crew finishes or leaves.
  • Job-site photo. One fix, attached to the photo record itself.
Not captured
  • Live-location map. Not streamed, not stored, not rendered.
  • Driving telemetry. We are not a fleet tool. No braking events.
  • Background location. The phone is not reporting when off the job.
07Data lifecycle

Your data, across its whole life.

No hidden copies. No secret retention.

01

Capture

Clock-ins, photos, quotes, and payments arrive over TLS 1.3. The server signs and timestamps every event before anything is stored.

02

Encrypt

Data is written through row-level security into an AES-256 at-rest volume. Attachments are encrypted before storage hands the upload back.

03

Replicate

Point-in-time snapshots and daily backups are copied to a second region. A backup that cannot restore is not a backup, so we test them.

04

Export

Export your customer, job, and payment data as CSV or JSON at any time. No support ticket, no retention bait.

05

Delete

Account closure triggers a 30-day hold, then a permanent purge across primary, replica, and backups. We publish the clock, we don't hide it.

08Honest gaps

What we don't ship yet, and where it's headed.

We would rather tell you the gaps up front than have you find them during a vendor review.

SSO / SAML

Roadmap, Q3 2026

No tenant-side SSO or SAML today. Enterprise SSO through Okta or Google Workspace is targeted for Q3 2026. If you need it sooner, talk to sales.

SOC 2 Type II

In progress, not yet audited

Controls are designed against SOC 2, but we have not yet completed a Type II audit. Email security@revcorepro.com for our internal controls letter.

Custom-domain portal

Roadmap

The Scale plan supports a white-label portal with your logo and brand color today. A fully custom domain on the homeowner portal is on the roadmap.

24/7 incident hotline

Email-first, business hours

security@revcorepro.com is monitored during weekday business hours, with an after-hours pager rotation for confirmed priority-one incidents.

09Transparency

Published, not promised.

We acknowledge reports within one business day, with a 90-day coordinated disclosure window. Material incidents are disclosed to affected customers within 24 hours.

Common questions, plainly answered.

Still wondering if RevCore fits your crew? Talk to our team →

Is RevCore Pro SOC 2 certified?

A SOC 2 Type II audit is in progress, with our controls mapped to the Trust Services Criteria. Email security@revcorepro.com for our current controls letter while the audit completes.

Where is customer data stored?

In the United States. Vercel edge plus Supabase on AWS us-east, with cross-region backups. No data is transferred abroad without your direction.

Has RevCore Pro had a security breach?

No breaches to date. If a material incident ever occurs, affected customers are notified within 24 hours in plain English.

How does RevCore Pro handle crew GPS and location?

We capture location at exactly three crew events, clock-in, clock-out, and job-site photos, to prove presence. There is no live-location map, no driving telemetry, and no background tracking.

Who at RevCore Pro can access my data?

Access is row-level and role-scoped. Service-role keys are held server-side only, and every privileged operation is logged. Internal access is least-privilege and reviewed.

Can I export my data? Can I delete it?

Yes to both. Export customers, jobs, and payments as CSV or JSON anytime. Account closure triggers a 30-day hold, then a permanent purge across primary, replica, and backups.

Your next kitchen table is a closing table.

Start free tonight and run tomorrow’s quotes, schedule, and payments from one login.

  • 14 days, full access
  • No credit card
  • No sales calls unless you ask

Rather talk it through first? Call (833) 555-0182. Monday–Friday, 7am–7pm CT, a human answers.

Estimates used to mean measuring, shooting photos, then two hours in Excel after dinner and a PDF emailed two days later. Half of those people had already signed with whoever quoted first. Now I build the good-better-best options in the truck and walk the homeowner through them at the kitchen table the same visit. Most sign right there, and the deposit clears before I'm off the street.
Tyler Mendoza
Tyler Mendoza
Summit Ridge Roofing · Roofing
Same day

card and ACH payouts

Under a week

to go live, migration included