Trust and security

Built for the sensitive work of recovery housing.

Roll Call holds resident records, incident notes, and house operations. This page describes the controls we have in place today and how we handle your data.

Updated August 18, 2026. Maintained by the Roll Call team as editable project content. It is not a third-party certification or independent audit.

Control summary

  • Role-based access for Directors, House Managers, and custom templates
  • Row-level security on customer-facing tables
  • Private storage for resident and incident files
  • HTTPS encryption in transit
  • Audit logs across major record types
  • Export and deletion available on request

Access and authentication

  • Email and password sign-in, with optional Google or Apple sign-in.
  • Role-based access: Directors and House Managers each see only what their role permits. Organizations can add named permission templates on top of those two roles.
  • House Managers are scoped to their assigned house; cross-house data is not exposed in the UI or API.
  • Sessions are managed by our auth provider and can be revoked by signing out.

Data protection

  • All traffic between your browser and Roll Call is encrypted over HTTPS.
  • Row-level security policies are enforced in the database for every customer-facing table.
  • Resident photos, incident photos, and incident attachments live in private storage buckets with signed, short-lived download URLs.
  • Service-role keys and webhook secrets are kept server-side and never shipped to the browser.

Hosting and infrastructure

  • Application code runs on Cloudflare's edge network.
  • Database, authentication, and storage are provided by Supabase (Postgres).
  • Email delivery uses Resend; calendar booking uses Calendly.
  • We do not self-host the database or run on personal infrastructure.

Data handling

  • We collect only the fields required to operate the workflows you use: residents, beds, incidents, chores, rent, meetings, and house notes.
  • Audit logs record who changed what and when across the major record types.
  • On request, your organization's data can be exported as CSV or deleted.
  • Specific retention windows, data processing agreements, and subprocessor commitments are available on request.
Subprocessors

Vendors that help run Roll Call.

The table below lists subprocessors already identified in our product and trust materials. For the current list in writing, email support.

Roll Call subprocessors
VendorPurposeData involved
CloudflareApplication hosting and edge networkApplication traffic and related operational metadata
SupabaseDatabase, authentication, and file storageAccount, house operations, and private file objects
ResendTransactional email deliveryEmail addresses and message metadata for product emails
CalendlyWalkthrough schedulingName, email, and scheduling details you submit when booking
GoogleOptional Google sign-inAccount email if you choose to sign in with Google
AppleOptional Apple sign-inAccount email if you choose to sign in with Apple
Lovable AI gatewayOptional relapse-risk screening prompt, Director opt-inOperational notes and incident text only when an organization enables the feature
Responsible AI

Optional screening help, not clinical care.

Roll Call includes an optional relapse-risk screening prompt that a Director can enable for their organization. It is off by default and opt-in.

When enabled, the feature produces a screening prompt for trained staff. It is not medical advice and not a diagnosis. Staff clinical judgment decides any action.

We do not claim HIPAA, BAA coverage, SOC 2, ISO 27001, or other formal certifications on this page. If your organization needs a signed DPA, BAA, or vendor questionnaire, contact us.

Shared responsibility

Security is a partnership.

Platform

Encrypted transport, managed database, managed auth, and private file storage provided by our hosting and backend providers.

Roll Call

Role-based access, row-level security policies, private buckets, audit logging, and least-privilege server functions.

Your team

Strong passwords, prompt removal of departing staff, and assigning each user the narrowest role they need to do their job.

Data rights

Export and deletion requests.

To request a data export or deletion for your organization, email support@rollcallhm.com with the subject line "Data export or deletion request." See also our privacy policy.

Contact

Reporting a concern.

To report a suspected security issue, request a data export or deletion, or ask for our current subprocessor list, contact the Roll Call team. We aim to acknowledge security reports within two business days.

Roll Call does not currently advertise SOC 2, HIPAA, ISO 27001, or other formal certifications. If your organization needs a signed DPA, BAA, or vendor questionnaire, reach out and we will work through it with you.

Back to home