Roof AI logo in black.
Solutions
Engage visitors

Turn website visitors into qualified leads

Book appointments

Schedule bookings and connect leads with agents

Nurture clients

Stay top-of-mind with timely, valuable outreach

Follow up intelligently

Close the loop on every lead before it slips away

Explore all solutions
Explore all solutions
Recent customer stories
Briggs Freeman
How Briggs Freeman delivered clear ROI with their AI assistant
7.5%
AI assistant lead-to-closed deal rate
Features
Natural language search

Help buyers find properties in their own words

AI conversations

Educate and engage with visitors in real-time

Integrations

Personalize with your CRM, MLS and company data

Explore all features
Explore all features
A shorten view of a chat between a homebuyer and Roof AI's assistant.
Add AI to your property listings
Turn listing traffic into showing requests automatically – without adding additional workflows.
For teams and brokerages
Explore Core
A shorten view of a chat between a homebuyer and Roof AI's assistant.
Add AI to your property listings
Turn listing traffic into showing requests automatically – without adding additional workflows.
For teams and brokerages
Resources
Customer stories

Explore success stories from Roof's customers

Education hub

Interactive demos that show you how the assistant works

Blog articles

Clear guides and actionable steps on real estate tech

Help center

Find simple answers, and solve issues fast

Explore all blog articles
Explore all resources
From the education hub
Find listings by address
Visitors arriving with a specific property in mind get instant results – no browsing required.
Explore this demo
CustomersPricing
LoginTalk to sales
Start for free

Security

Updated on: December 19, 2024

Thank you for trusting Roof AI with your customers’ personal data. We take this responsibility very seriously and make every effort to be transparent and careful when handling this data on your behalf.

Roof AI uses industry standard technologies and services to secure your data from unauthorized access, disclosure, inappropriate use, and loss of access. We ensure that the security policies of all our sub-processors are documented and up-to-date with industry compliance standards where required (GDPR, etc).

Security at Roof AI is overseen by our Chief Executive Officer and carried out by our entire team.

Vulnerability Disclosure

If you would like to report a vulnerability, please contact security@roof.ai with a proof of concept, list of tools used, and the output of the tools.

If a security disclosure is received, we will work quickly to reproduce each vulnerability to verify its status before taking the steps needed to remedy.

Compliance

GDPR

Roof AI is compliant with the GDPR. If you have customers who reside in the European Union and use Roof AI then we recommend that you sign a Data Processing Agreement (DPA) with Roof AI. This document is a contractual agreement that recognizes Roof AI as being GDPR compliant and makes your organization GDPR-compliant when it comes to using Roof AI as a sub-processor.

Any person (including EU residents) wishing to submit a personal data request to Roof AI may do so by sending an email to privacy@roof.ai explaining their data request.

Infrastructure and Network Security

Servers

Roof AI infrastructure is hosted on Google Cloud Platform (GCP). The GCP data centers are equipped with multiple levels of physical access barriers, that include:

  • Alarms
  • Perimeter Fencing
  • Vehicle Crash Barriers
  • Custom-designed Electronic Access Cards
  • Metal Detectors
  • Internal Trip-Lights
  • Biometrics

For more information on GCP Security features, you can refer to this website. Roof AI employees do not have physical access to GCP data centers, servers, network equipment, or storage.

Logical Access Control

Roof AI has full control over all its infrastructure on GCP, and only authorized team members at Roof AI have access to configure infrastructure when needed in order to add new functionality, or respond to incidents. All access required for control of infrastructure has mandated two-factor (2FA) authentication. The levels of authorization for infrastructure components is mandated by the principle of least privilege.

Penetration Testing

Roof AI undergoes grey box penetration testing conducted by an independent third-party agency on an annual basis. For grey box penetration testing, Roof AI will provide the agency with an overview of application architecture and information about system endpoints.

Information about any security vulnerabilities successfully exploited through penetration testing is used to set mitigation and remediation priorities.

Intrusion Detection

GCP Security Command Center helps us identify potential security threats, suspicious activity and compliance violations. This notifies us on common alert channels whenever suspicious activity may occur. Our team will check each alert, investigate the activity, and then respond accordingly.

Business Continuity and Disaster Recovery

High Availability

Every part of the Roof AI service uses properly-provisioned, redundant servers (e.g. web servers, replica databases) in the case of failure. We do implement gradual rollout and rollback of services in the case of deployment errors.

Business Continuity

Roof AI keeps daily backups of our production databases in a data center outside of the production region (i.e RPO is no greater than 24 hours).

Disaster Recovery

In the event of a prolonged region-wide outage, the Roof AI team will follow its recovery runbooks to bring up a production environment in a different region (we aim for a RTO of 24 hours or less).

Data Flow

Data Into System

Roof AI provides an embeddable web window for use on our clients’ websites for users to interact with a client's personal chatbot. This chat window will send data back to Roof AI's APIs over TLS 1.2 or greater.

Data Through System

Data exchanged between end-user chat platforms and Roof AI backend is encrypted with TLS 1.2 or greater.

Data Out of System

We employ different tools in our production network to mitigate and detect potential data exfiltration. We scrutinize our preferred partners and integrations to ensure that they comply with necessary security regulations (GDPR, etc), before transferring data for processing.

Data Security and Privacy

Data Encryption

All data in Roof AI servers is automatically encrypted at rest. All volumes are encrypted in GCP using the industry-standard AES-256 algorithm.

Roof AI only ever sends data over TLS 1.2 or greater, and never downgrades connections to insecure early TLS methods like SSLv3 or TLS 1.0.

Data Removal

Data may be retained after termination of service according to specification within our main customer contract. If data is kept after termination of service for machine learning training purposes, Roof AI will scrub all personally identifiable information (PII) from customer data. This includes, but is not limited to, names, emails, phone numbers, IPs.

Application Security

We use a combination of automated and manual inspection to determine if new vulnerabilities are introduced in the software packages on our systems (including, but not limited to, GCP Cloud Armor and Web Security Scanner, Sonarcloud, Snyk and Github dependabot). Our Infrastructure team ingests security bulletins and prioritizes remediation according to our internal Security Vulnerability Identification documentation.

Two-Factor Authentication

In addition to password login, two-factor authentication (2FA) provides an added layer of security to Roof AI via a time-based one-time password algorithm (TOTP). We encourage 2FA as an important step towards securing data access from intruders.

Roof AI supports 2FA for all user accounts that require authentication.

Corporate Security

Risk Management

Roof AI uses the NIST CyberSecurity Framework (CSF) to guide and manage our cybersecurity-related risks.

Security Policies

Roof AI maintains internal copies of security documentation, which are updated on an ongoing basis and reviewed annually for gaps:

  • Business Continuity Plan
  • Access Control Policy
  • Data Handling & Encryption Policy
  • Security Incidence Management Policy

Background Checks

Roof AI conducts a mandatory background check and reference check for all employees prior to joining our team.

Disclosure Policy

In the event of a data breach, Roof AI defers to GDPR regulations, which maintains that customers shall be notified within 72 hours of a data breach, where feasible.

Roof AI maintains a live report of operational uptime and issues on our status page. Anyone can subscribe to updates via email from the status page.

For real estate brokerages and teams

For real estate brokerages and teams

Tailored to help your real estate business grow through intelligent automation.
Talk to sales
Start for free
Solutions
Engage visitorsBook appointmentsNurture clientsFollow up intelligently
Features
Natural language searchAI conversationsIntegrations
Resources
Education hubHelp centerProduct updatesBlog articles
Company
MissionCustomer storiesLoginPricing
Legal
Acceptable use policyTerms of servicePrivacy policy
Roof AI logo in black.
BHHS Chicago icon
Harry Norman FGP icon
Baird & Warner icon
Edina Realty icon
Long Realty icon
Keyes icon
Remax icon
100+
© 2026 Roof AI Inc. All rights reserved.