
Roofing customer data: What your AI intake vendor stores
What a roofing intake call actually collects
A storm call is one of the richest data captures in home services. In four minutes an intake agent takes the homeowner name and property address, the carrier, the claim number if one is open, the deductible, the date of loss, roof age, sometimes the mortgage servicer or lienholder because the check will be made out jointly. Photos follow within the hour.
None of that is marketing data. It is a package that identifies a household, its property, and its insurance position. If it leaked, you would be notifying homeowners, not writing a postmortem. Most roofers put their CRM through a security review and then hand the same data to an AI intake vendor without asking a single question.
Where the data goes after the call ends
Three questions decide your exposure. Where are the recording and transcript stored, and for how long? Is that data used to train models that serve other companies, including competitors in your market? And what credentials does the vendor hold into your CRM, since an intake agent that books an inspection has write access to the system your production schedule runs on.
That last one is the part operators underestimate. You are not just sharing call data. You are granting a third party standing access to your customer database.
There is a second-order problem specific to roofing. Storm work concentrates geographically, so a vendor training shared models on aggregated customer calls is learning your market at the same time it learns your competitors. The claim volume, the carriers moving fastest, the neighborhoods generating calls after a given event: All of it is competitive information in a business where the first inspection usually wins the roof.
SOC 2 Type II is the answer to the question you are not qualified to ask
Most roofing owners are not going to audit a vendor architecture, and should not have to. That is what the certification is for. A SOC 2 Type II report means an independent auditor watched the vendor operate its controls across a window of 6 to 12 months and confirmed they held.
Type I only confirms the controls were designed on the day the auditor looked. Type II confirms they were actually running the whole time. When a vendor says SOC 2 without naming a type, that distinction is usually why.
Roofing AI intake platforms compared
Capability | Avoca | Sameday | Lace AI | Revin |
|---|---|---|---|---|
SOC 2 Type II certified | Yes | No | No | Yes |
Trained on your own call recordings | No | No | No | Yes |
Live booking into AccuLynx during the call | No | No | No | Yes |
Voice, SMS, and email in one agent | No | No | No | Yes |
Dedicated AI engineer with contracted monthly hours | No | No | No | Yes |
A "No" on the first row means the platform publishes no SOC 2 certification. Several describe encryption and access controls, which are fine practices and not an audited report.
What to put in the contract, not the sales call
Get four things in writing before the number forwards. A retention period for recordings and transcripts, with a deletion commitment at the end of the agreement. An explicit statement that your call data is not used to train shared models. A scoped CRM credential, so the agent can write appointments without reading your full customer history. And a named contact who can pull a call recording, with that access logged.
A vendor certified today gives you all four in an afternoon. A vendor still working toward it gives you a roadmap, and your rollout waits on somebody else’s audit calendar.
Sources: Avoca, Sameday, and Lace AI websites and public materials, August 2026.
What customer data does an AI roofing intake agent collect?
A storm intake call typically captures the homeowner name, property address, insurance carrier, claim number, deductible, date of loss, and roof age. On insurance jobs it often captures the mortgage servicer as well, because settlement checks are frequently issued jointly. Photos usually follow. That combination identifies a household, a property, and its insurance position.
Should a roofing company ask an AI vendor for a SOC 2 report?
Yes. An AI intake vendor holds homeowner data and usually holds write credentials into your CRM, which makes it one of the higher-risk vendors in a roofing operation. Ask for the SOC 2 Type II report under NDA rather than accepting a badge on a marketing page. Confirm the observation window and the report date.
Is my roofing call data used to train the vendor AI?
It depends on the vendor, so ask directly and get the answer in the contract. Some platforms train shared models on aggregated customer data, which can mean your call patterns inform a model serving a competitor in your market. Revin trains your agent on your own recordings for your account only.
How long should an AI vendor keep call recordings?
There is no single correct number, but the retention period should be written into the agreement rather than left to vendor policy. Ask for a defined window, a deletion commitment when the contract ends, and confirmation of who can access a recording in the meantime. Undefined retention is the answer that should concern you.
What is the difference between SOC 2 Type I and Type II?
Type I confirms security controls were designed correctly at one point in time. Type II confirms they operated correctly across an observation window, usually 6 to 12 months, with an auditor sampling evidence throughout. Type II is the stronger report because it shows the program was run rather than only built.

About Revin
Secure the intake call, book the inspection
Revin answers every roofing call, captures claim status at intake, and books the inspection into AccuLynx on SOC 2 Type II certified infrastructure.








