Get a Quote

Home Services App Security Audits

HVAC, plumbing, electrical, pest, cleaning, and landscaping businesses now hold an unusually dangerous data combination - home addresses, gate and alarm codes, occupancy schedules, and cards-on-file - inside booking apps built with AI. 48% of trade pros already use AI tools, and Veracode found 45% of AI-generated code fails security checks.

Get a Free Security Scan See Our AI App Audit
What breaks in vibe-coded home-services apps

Six risks unique to home-services apps

Field-service apps pair exact home addresses with physical-entry information - a data combination most industries never have to think about securing.

Booking sites with no row-level security

AI-scaffolded databases (Lovable/Bolt plus Supabase) commonly ship with row-level security disabled. CVE-2025-48757 exposed 170+ Lovable apps' full tables - emails, payment details - to anyone with browser dev tools, reported March 2025.

Customer portals holding gate & alarm codes

Property notes routinely contain gate codes, alarm codes, key locations, and pet warnings. A leaked table isn't just a privacy incident - it's a burglary target list. The precedent for how badly access data gets abused: an ADT technician accessed roughly 200 customers' camera accounts 9,600+ times over 4.5 years before being sentenced by the DOJ.

Quote/estimate forms wired to auto-texting

51% of AI-using trade pros already use AI for estimates and quoting. If a quote form is wired to automatic texting without documented consent, each message is a – TCPA violation - home services sit among the top categories for TCPA litigation, and NexGen Air Conditioning paid to settle a ringless-voicemail case in November 2025.

Card-on-file for recurring maintenance plans

Membership and maintenance-plan billing means stored payment credentials and monthly rebills. A vibe-coded billing flow that touches card data directly instead of a tokenized processor drags the whole app into PCI scope - –nth in fines plus possible loss of processing, on top of California's AB 2863 auto-renewal consent requirements (effective July 1, 2025).

Dispatch/tech GPS apps as an occupancy feed

Dispatch apps know exactly which houses are empty and when service windows occur. An exposed jobs-today API is a real-time "nobody's home" feed. On the employee side, GPS tracking of company vehicles without written notice is separately illegal in states like New Jersey.

AI review-generation tools

52% of AI-using pros already apply AI to customer communication and follow-up. Tools that auto-draft, incentivize, or filter reviews cross the FTC's fake-review rule (effective October 21, 2024), which carries civil penalties up to per violation - a real risk given reviews are the #1 acquisition channel in local trades.

Regulatory exposure

What applies to your home-services app

RegulationWhen it appliesPenalty
TCPA + FCC revocation ruleMarketing calls/texts/ringless voicemail without consent; opt-out not honored within 10 business days (eff. 2025-04-11)– per call/text; NexGen paid .8M
PCI DSSStoring/processing cards - card-on-file for memberships and recurring billing–nth via acquiring bank; loss of processing
CCPA/CPRA + state privacy lawsRevenue/consumer thresholds met; lead lists count toward totals/violation, intentional; CPPA record actions in 2025
FTC Safeguards Rule (GLBA)Offering or arranging customer financing (common for HVAC replacements)FTC breach reporting required within 30 days for 500+ consumers
State contractor licensing (e.g. CA CSLB)License number must appear on all advertising, including websites– first advertising offense; up to + jail for unlicensed contracting
CA Auto-Renewal Law (AB 2863)Auto-renewing maintenance plans sold online, effective 2025-07-01CA UCL enforcement/restitution; consent records must be kept 3+ years
FTC Fake Review RuleAI-generated, fake, incentivized, or suppressed reviewsUp to per violation
Fix checklist

What we check in a home-services app security audit

  • Row-level security enabled on customer, property-notes, and booking tables
  • Gate/alarm codes and access notes encrypted and scoped only to the assigned technician
  • TCPA opt-in consent captured and revocations honored within 10 business days
  • Card-on-file tokenized through a processor, never stored directly in your database
  • Auto-renewal consent records retained 3+ years per California's AB 2863
  • Employee vehicle GPS tracking backed by written notice where state law requires it
  • Review-collection tools checked against the FTC's fake-review rule (no gating/incentivizing)
  • Contractor license number displayed on the site per state advertising requirements
FAQ

Home services app security questions

Is my Lovable or Bolt-built HVAC or plumbing booking app secure enough?

Not by default. AI-generated code fails security checks in roughly 45% of tasks (Veracode), and CVE-2025-48757 exposed 170+ Lovable apps' full databases because row-level security was off by default. A booking app holding customer addresses and property-access notes needs that checked before launch.

Are gate codes and alarm codes in my customer database a security risk?

Yes, a serious one. Property notes with gate codes, alarm codes, and key locations amount to a burglary target list if exposed. An ADT technician's abuse of camera access - roughly 200 customers, 9,600+ unauthorized views over 4.5 years - shows how badly this kind of access data can be misused even by insiders.

Do I need TCPA consent to text customers appointment reminders?

Yes, for marketing and promotional texts. Violations carry – per text, and home services is among the most-litigated TCPA categories - NexGen Air Conditioning paid in November 2025 to settle a ringless-voicemail case with roughly 181,135 class members.

What is California's Auto-Renewal Law and does it apply to my maintenance plans?

Yes, if you sell auto-renewing maintenance or service plans online to California customers. AB 2863, effective July 1, 2025, requires you to retain proof of consent for at least 3 years and let customers cancel through the same medium they used to sign up.

Can I use AI to generate or manage customer reviews?

Not if it gates, incentivizes, or fabricates reviews. The FTC's fake-review rule, effective October 21, 2024, carries civil penalties up to per violation - a meaningful risk since reviews are the top acquisition channel for most local trades.

What should I do if my home-services app's database was exposed?

Rotate every API key and credential, enable row-level security if it wasn't already on, and treat any exposed gate codes or access notes as an urgent physical-security issue for affected customers, not just a data-privacy one. Notify affected customers under applicable state breach laws.

A leaked customer database with gate codes isn't a privacy incident, it's a break-in list

We audit AI-built home-services booking and customer-portal apps for exposed access data, missing RLS, and TCPA/PCI gaps - then fix what we find.

Get a Free Security Scan