
Roofbuddy processes NZD $78.7 million as it transforms roofing
The first principle that became part of our DNA was to test everything under real-world conditions. To call the system we entered the market with in May 2022, a BETA would be generous, we pushed the envelope for what could be called a minimum viable product and went straight into the market to transact. It was messy, uncomfortable, time-consuming and incredibly manual, but it worked (just). 3 transactions in May, 15 in June and 10 in July - it was like the Wright Brothers prototype; off the ground, and we built the rest while we were in flight.
Ukraine's drone industry has transformed from nascent to world-leading in under 3 years. For this very reason, they didn't have the best people, tech, or abundant funding - the advantage they had was real-time battlefield testing. Test in the real world, fail fast, measure results, adapt, iterate and optimise - this is one of our core values we discuss internally as a "culture of continuous improvement".
Secondly, money talks AND pays the bills, transacting early generates revenue that fuels growth and covers costs. If you are profitable, the runway is infinite, you retain your autonomy, set terms for investors or eschew them altogether and exist in a healthy 'growth management' mindset. The Eisenhower Matrix, Pareto Principle and Elon's much-touted "First Principles Thinking" all guide the Roofbuddy team to the same conclusion - earning income and remaining profitable is core. It follows that supporting revenue growth has been the tech team's primary prerogative from the outset.
We have built more than our fair share of zombie features that didn't commercialise as anticipated - that's healthy attrition. However, if every epic, sprint and ticket is viewed through the lens of increasing revenue or decreasing cost, prioritisation becomes incredibly simple - estimate by magnitude and execute.
The Roofbuddy marketplace has been an ambitious, tech-driven reimagining of how roofing transactions are conducted - so far as we know, we are the greatest (only) roofing, sales, tech, price aggregation marketplace in the world. When Uber and Airbnb started growing parabolically, they got significant blowback from market incumbents with entrenched vested interests. We have seen a bit of that ourselves, too and anticipate more. Transcending these 'speed limit' warnings is all about value creation - how is our product and service making the lives of our users easier and better? Roofers can quote a job in 2 minutes instead of 2 hours - that's measurable value created. Customers can get multiple competitive, comparable quotes in 24 hours instead of 24 days - more value.
A core function of technology is to systematise and rationalise complex information and distil it down into its functional essence - in Roofbuddy's case, that means answering one question as quickly and accurately as possible: What is the price? The extent to which we have made that easier for our Roofing partners to calculate and our customers to receive and understand; that is the value we have created. True value is immutable; Trademe is not a garage sale.
Napoleon's Grand Armée conquered the entire European continent in an administratively led war of self-defence, ostensibly. This revolution in military affairs had nothing to do with better muskets, cannons or ships. It was a revolution of meritocratic management, administration, supply chain, logistics and information flow - doing the boring stuff several orders of magnitude better than competitors was (and still is) the path to total victory. Creating our own proprietary CRM as opposed to grafting our tech stack onto an existing offering was a huge inflection point but dividends abound.
It's allowed us unconstrained flexibility and freedom of movement to handle internal and external workflows in a profoundly efficient way. Like the proverbial marble run, our proprietary CRM now serves and automates the information and workflow between customers, roofers and our staff to achieve an unprecedented level of service, accuracy of information and end-to-end workflow management. Roofbuddy's tech excels in the 'boring' details, and it's been a boon for team morale and overall performance. Plugging another of Roofbuddy's values at this point seems inevitable - "esprit de corps"; my penchant for military history foisted on my poor unsuspecting colleagues at every opportunity - and now you too.
At Roofbuddy, performance is tangible and measurable across all departments. In 3 years, the Roofbuddy marketplace has served 35,469 unique customer enquiries, delivered 39,325 quotes and processed 3,594 orders totalling $78,707,202.51 in roofing services transacted; we measure innumerable performance metrics that instruct daily discussion and action. Our mature codebase (~2964 commits) sees ~3.3 commits and 1.5 deployments daily, with a robust CI/CD pipeline achieving 100% successful builds, thanks to extensive frontloaded checks. We maintain 71% test coverage, uphold a 99% uptime, and average a 2-minute rollback, ensuring rapid recovery from any issues.
New developers land their first meaningful commit within 10 days, reflecting our inclusive, fast-moving culture. Our developers aren't hidden away in caves - they're deeply embedded in real-world problems, working shoulder-to-shoulder with the front line team. From the very start, our engineers are shaped to be product champions, not just coders, ensuring that every line they write solves meaningful challenges. Without a scoreboard, it's just exercise.
Roofbuddy enjoys a fantastic culture of high performance and achievement, and I'm proud of the results the team have delivered over the last 3 years - we aspire to be a bright spot of innovation and kiwi dynamism during a bleak and attritional economic period for Aotearoa. We believe we are building unique tripartite, transactional, marketplace technology that can be adapted and utilised in hundreds of different countries and thousands of different industries; Roofbuddy's CTO, Igi Manaloto, just had an involuntary heart palpitation as I wrote that.
We have achieved profound product market fit, proof of concept and dramatically altered the transactional dynamics in the Roofing industry - to some incumbents' chagrin. So far, we have greatly improved the level of service and value for money customers can expect from a roofing service provider, that's only been possible with our tech-first approach, and there is much more work to do! Our proprietary tech stack is portable, dynamic and can be deployed into different verticals and horizontals at scale; so we are extremely excited to see how far we can go in New Zealand and abroad over the coming years.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles

1News
10 hours ago
- 1News
Phones are covered in germs. A tech expert explains how to clean them
We wash our hands, sanitise shopping trolleys and wipe down cafe tables. But what about our phones? We touch these devices dozens of times a day, and take them everywhere from the kitchen to the dining table, and even the bathroom, writes Australian academic and technology expert Meena Jha. Phones can be contaminated with many kinds of potential germs. When was the last time you wiped down yours – and with what? If you use the wrong cleaning agents or tools, you could strip your phone's protective coatings, degrade waterproof seals, or even affect its touch sensitivity. Do phones really need cleaning? Touchscreens get covered in fingerprints and smudges, so there are aesthetic and functional reasons to wipe down your screen. ADVERTISEMENT Another reason comes down to potential health concerns. Whenever mobile phones are swabbed for microorganisms, scientists inevitably find hundreds of species of bacteria and viruses. While not all of these cause sickness, the potential for transmission is there. We use phones while in the bathroom and then put them near our mouths, touch them while eating, and pass them between people in meetings, cafes, parties and classrooms. Unlike hands, which can be washed many times a day, phones are rarely cleaned properly – if at all. If you do want to sanitise your phone, it's also important to not damage it in the process. Some cleaning products will damage your phone (Source: Getty) You might think a quick swipe with a household cleaner or hand sanitiser is a clever shortcut to keeping your phone clean. However, many of these products can actually degrade your device's surface and internal components over time. ADVERTISEMENT For example, both Apple and Samsung advise against using bleach, hydrogen peroxide, vinegar, aerosol sprays, window cleaners or high-concentration alcohol wipes (above 70%) on their devices. Most smartphones are coated with an oleophobic layer – a thin film that helps resist fingerprints and smudges. Harsh chemicals such as alcohols, acetone or ammonia-based cleaners can strip this coating, making your screen more vulnerable to smudging, and diminished touch responsiveness. Vinegar, a common DIY disinfectant, can corrode aluminium or plastic edges due to its high acidity. Bleach and hydrogen peroxide, though highly effective as disinfectants, are also too aggressive for the delicate materials used in consumer electronics. High-alcohol content wipes may dry out plastics and make them brittle with repeated use. In short: if the cleaner is tough enough to disinfect your kitchen bench, it is probably too harsh for your phone. How should I clean my phone then? (Source: Getty) ADVERTISEMENT The good news is that cleaning your phone properly is simple and inexpensive. You just need to follow the guidelines backed by major manufacturers. You should also unplug and remove any protective cases or accessories when cleaning your phone. Most tech companies recommend using 70% isopropyl alcohol wipes (not higher), soft microfibre cloths, and anti-static soft-bristled brushes made of nylon, horsehair or goat hair to clean delicate areas like speaker grills and charging ports. During the Covid pandemic, Apple revised its cleaning guidelines to permit the use of Clorox disinfecting wipes and 70% isopropyl alcohol on iPhones, provided they are used gently to avoid damaging screen coatings or allowing moisture to seep into the device. Samsung offers similar advice, recommending users wipe down their phones with a microfibre cloth lightly dampened with a 70% alcohol solution, while steering clear of direct application to ports and openings. Prevent accidental damage when using these tips (Source: Getty) Never spray liquid directly onto the phone, as moisture can seep into ports and internal components, leading to short circuits or corrosion. ADVERTISEMENT Submerging your phone in any cleaning solution is also risky, even for water-resistant models: the seals that prevent water from getting in, such as rubber gaskets, adhesives, nano-coatings and silicone layers, can degrade over time. Avoid using paper towels, tissues, or rough cloths which may leave scratches on the screen or shed lint that clogs openings. Finally, be cautious about over-cleaning. Excessive wiping or scrubbing can wear down protective coatings, making your phone more susceptible to fingerprints, smudges, and long-term surface damage. How often should I clean my phone? (Source: Getty) While there is no strict rule for how often you should clean your phone, giving it a proper wipe-down at least once a week under normal use would make sense. If you regularly take your phone into high-risk environments such as public transport, hospitals, gyms, or bathrooms it is wise to clean it more frequently. ADVERTISEMENT If you're serious about hygiene, cleaning not just your hands but one of the things you touch most every single day makes sense. Doing it wrong can slowly damage your device. But doing it right is simple, affordable, and doesn't take much time. Meena Jha is the head technology and pedagogy cluster CML-NET at Australia's CQUniversity. This article is republished from The Conversation under a Creative Commons license.


Techday NZ
10 hours ago
- Techday NZ
SquareX to unveil browser, passkey flaws at Black Hat, DEF CON
SquareX researchers are set to present a series of vulnerability disclosures relating to browser security at two major security events in August. During Black Hat USA and DEF CON 33, SquareX will reveal a number of architectural vulnerabilities impacting passkey authentication systems, enterprise data loss prevention solutions, and browser extensions. The company's researchers plan to deliver multiple talks that aim to detail new techniques attackers may use to circumvent existing security measures. Browser-first world At Black Hat USA, the presentation titled "Browser-Native Security in a Browser First World" will be delivered by Vivek Ramachandran, Founder of SquareX. This talk is expected to cover the growing dependency enterprises have on web browsers and the resulting security challenges. With staff reportedly spending up to 80% of their device usage time within browsers, defending against browser-based threats has become a critical concern. Ramachandran's talk will highlight current tactics, techniques, and procedures (TTPs) that enable attackers to bypass technologies such as Secure Access Service Edge (SASE), endpoint detection and response (EDR), and endpoint data loss prevention (DLP) tools. Passkey vulnerabilities DEF CON 33 will feature Shourya Pratap Singh, Jonathan Lin and Daniel Seetoh presenting research under the session title "Passkeys Pwned: Turning WebAuthn Against Itself." This discussion will focus on a new technique designed to subvert passkey authentication. Passkeys, which have seen significant uptake among major technology providers such as Apple, Google, and Microsoft, are promoted as a more secure alternative to traditional passwords. Despite this positioning, SquareX's research asserts that vulnerabilities still exist. "Over the past year, we have been releasing bleeding edge research on architectural browser vulnerabilities as part of the Year of Browser Bugs project. We believe that deeply understanding the attacker mindset is the only way to defend against the newest threat vectors, and we believe that it is critical to share these findings at industry leading conferences like Black Hat and DEF CON. This year's research demonstrates critical gaps that traditional security solutions simply cannot address - everything from passkey to browser extension vulnerabilities. We will also be sharing multiple open source browser-native security tools that enterprises need to plug the browser security gap," said Vivek Ramachandran, Founder of SquareX. Browser extension threats In addition to the mainstage talks, Nishant Sharma and Shourya Pratap Singh will present "Plug and Prey: Scanning and Scoring Browser Extensions" at Recon Village. Their session introduces ExtHuntr, an open-source tool developed to scan for installed browser extensions, analyse their permissions and behaviour, and generate risk scores. ExtHuntr aims to provide security teams with greater visibility into potential risks posed by browser extensions. SquareX will also run a demonstration called "Copycat: Identity Stealer Extension" and a session titled "Angry Magpie: DLP Bypass Simulator" at DEF CON 33 Demo Labs, underscoring the firm's focus on practical, real-world attack simulation tools related to browser security. Cloud security workshop Nishant Sharma, Head of Security Research at SquareX, is scheduled to conduct a workshop at Cloud Village, titled "Serverless but Not Defenceless: A Security Deep Dive into Cloud Run." The workshop will provide attendees with detailed guidance on how to deploy and manage services on Google Cloud Run securely, using principles drawn from DevSecOps and related practices. Security field manual Audrey Adeline, a SquareX researcher, will participate in "The Trailblazer's Guide to Cybersecurity" discussion at Black Hat USA. Topics will include the experiences of professionals who are first-generation entrants to the cybersecurity sector. Adeline will also share information about the release of The Browser Security Field Manual, a book written in collaboration with chief information security officers (CISOs) from Fortune 500 companies and major technology firms. The manual addresses contemporary attacks targeting employees via browsers and provides guidance on defensive techniques. Event schedule In addition to the headline talks, SquareX researchers will lead several demonstration sessions and workshops at both Black Hat USA and DEF CON 33. These include practical labs showing browser-based identity theft and DLP bypass scenarios, as well as further engagements focusing on serverless security and browser-native security tools. The presentations are designed to highlight what SquareX claims are critical gaps in existing security technology, particularly where traditional solutions may not adequately address emerging attack vectors related to browsers, passkeys, and extensions.

1News
21 hours ago
- 1News
Google loses appeal in antitrust battle with Fortnite maker
A US federal appeals court has upheld a jury verdict condemning Google's Android app store as an illegal monopoly, clearing the way for a federal judge to enforce a potentially disruptive shakeup that's designed to give consumers more choices. The unanimous ruling issued by the Ninth Circuit Court of Appeals delivers a double-barreled legal blow for Google, which has been waylaid in three separate antitrust trials that resulted in different pillars of its internet empire being declared as domineering scofflaws monopolies since late 2023. The unsuccessful appeal represents a major victory for video game maker Epic Games, which launched a legal crusade targeting Google's Play Store for Android apps and Apple's iPhone app store nearly five years ago in an attempt to bypass exclusive payment processing systems that charged 15% to 30% commissions on in-app transactions. The jury's December 2023 rebuke of Google's app store for Android-powered smartphones began a cascade of setbacks that includes monopoly judgements against the company's ubiquitous search engine last year and the technology underlying its digital ad network earlier this year. Although not as lucrative as Google's search engine or ad system, the Play Store for Android apps has long been a gold mine that generated billions of dollars in annual revenue by taking a 15% to 30% cut from in-app transactions funneled through the company's own payment processing system. ADVERTISEMENT Following a month-long trial, a nine-person jury determined that Google had rigged its system to thwart alternative app stores from offering better deals to consumers and software developers. That verdict resulted in US District Judge James Donato ordering Google to tear down digital walls shielding the Play Store from competition, triggering the company's appeal to overturn the jury's finding and void the judge's mandated shakeup. But a three-judge panel that heard Google's appeal in February rejected its lawyers' contention that Donato erred by allowing the case to be determined by a jury that deviated from the market definition outlined by another federal judge who mostly sided with Apple in Epic's case against the iPhone maker's app store. Epic's lawsuit "was replete with evidence that Google's anticompetitive conduct entrenched its dominance, causing the Play Store to benefit from network effects", the judges wrote in the decision. The ruling "will significantly harm user safety, limit choice, and undermine the innovation that has always been central to the Android ecosystem", Google's vice president of regulatory affairs Lee-Anne Mulholland said in a statement. Unless Google can extend the enforcement delay placed on Donato's order issued last October, the company will have to begin an overhaul that includes making the Play Store's entire library of more than 2 million Android apps available to would-be rivals and also help distribute the alternative options. Google has argued that the required revisions will raise privacy and security risks by exposing consumers to scam artists and hackers masquerading as legitimate app stores. But Epic's lawyers have ridiculed Google's warnings about the changes as scare tactics in a desperate attempt to protect the fortunes of its corporate parent Alphabet Inc. Although Epic fell short in its attempt to have the iPhone's app store declared a monopoly, that case resulted in a judge issuing an order that required Apple to surrender exclusive control over the payment processing of in-app transactions and allow links to alternative systems without collecting a commission. ADVERTISEMENT Besides being hit with Donato's order, Google still faces further trouble ahead that could leave an even bigger dent in its finances. As part of the effort to address Google's illegal monopoly in search, a federal judge is weighing a proposal by the US Justice Department that would require the sale of its Chrome web browser and ban the multibillion dollar deals that company has been making with Apple and others to lock-in its search engine as the main gateway to the internet. Google is also facing a proposed breakup of its advertising technology as part of the countermeasures to its monopoly in that business. A trial on that proposal was scheduled to begin in September.