Trust

Security and Responsible Use

A summary of Roof Quote Analyzer safeguards and responsible disclosure guidance.

Updated: August 23, 2026

Current safeguards

  • HTTPS for the public site and Roof Quote Analyzer application
  • CSRF protections and secure browser security headers
  • Content-type validation, file-size limits, and normalized upload handling
  • Short-lived customer job storage with automatic deletion configured within 72 hours
  • Controlled job concurrency and daily service limits
  • A deliberately limited personalized preview while complete report findings and files remain inaccessible before purchase
  • Stripe-hosted Checkout so full card details do not pass through the Roof Quote Analyzer application server
  • Checkout only after a completed analysis and preview, with manual capture before the report files are released
  • High-entropy, short-lived paid-report URLs emailed only after verified payment capture
  • Paid-report delivery messages contain expiring links rather than attached customer quote documents
  • Restricted operator access to hosting, payment, and API credentials

Responsible disclosure

Send suspected vulnerabilities to support@understanddecide.com. Include the affected URL, steps to reproduce, expected and actual behavior, and any screenshots that do not expose another person’s documents or personal information.

Do not access, modify, retain, or share data belonging to another user. Do not disrupt the service, perform denial-of-service testing, use automated high-volume scanning, or publicly disclose a vulnerability before we have had a reasonable opportunity to review it.

No bug bounty

Understand / Decide does not currently operate a paid bug-bounty program. A good-faith report is still appreciated.

Security limits

No internet service is perfectly secure. The safeguards listed here describe the current configuration and are not a warranty or certification.