Security & Data Protection

Your data security is our highest priority. BuilderMate implements enterprise-grade security measures to protect your construction business data.

Data Encryption

In Transit

  • 256-bit SSL/TLS encryption for all data transmission
  • HTTPS enforced across all BuilderMate services
  • Secure API connections to integrations
  • Perfect Forward Secrecy (PFS) enabled

At Rest

  • AES-256 encryption for database storage
  • Encrypted file storage for documents and photos
  • Encrypted backups stored in multiple locations
  • Encryption keys rotated regularly

Infrastructure Security

  • Hosted on AWS with SOC 2 Type II certified data centers
  • Geographic redundancy across multiple availability zones
  • DDoS protection and web application firewall
  • 24/7 infrastructure monitoring and alerting
  • Automated security patching

Application Security

  • Regular penetration testing by third-party security firms
  • Automated vulnerability scanning
  • Secure coding practices and code reviews
  • Input validation and SQL injection prevention
  • XSS and CSRF protection
  • Rate limiting and brute force protection

Access Controls

  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA) available
  • Strong password requirements
  • Session timeout after inactivity
  • IP whitelisting available for enterprise plans
  • Audit logs of all data access

Data Backup & Recovery

  • Automated daily backups
  • Point-in-time recovery up to 30 days
  • Backups stored in geographically distributed locations
  • Regular disaster recovery testing
  • 99.9% uptime SLA

Compliance

  • SOC 2 Type II certified (annual audits)
  • GDPR compliant for European customers
  • CCPA compliant for California residents
  • PCI DSS Level 1 compliant (via Stripe)
  • HIPAA compliance available for enterprise

Employee Access

  • Background checks for all employees
  • Security training for all staff
  • Least-privilege access principles
  • All access logged and monitored
  • NDA agreements with all employees

Incident Response

We maintain a comprehensive security incident response plan:

  • 24/7 security monitoring and alerting
  • Dedicated incident response team
  • Notification within 72 hours of confirmed breach
  • Post-incident analysis and improvements

Third-Party Security

All third-party services undergo security review:

  • AWS (infrastructure hosting)
  • Stripe (payment processing - PCI DSS Level 1)
  • Twilio (SMS delivery)
  • SendGrid (email delivery)

Data Privacy

  • We never sell your data
  • Data isolation between customer accounts
  • You own your data - export anytime
  • Data deletion available upon request
  • Geographic data residency options

Security Questions?

We're transparent about our security practices. Contact our security team:
Email: [email protected]

For vulnerability reports, please use our responsible disclosure program.

Enterprise Security

Need additional security features? Our Enterprise plan includes:

  • Single Sign-On (SSO) via SAML 2.0
  • Advanced audit logging
  • IP whitelisting
  • Custom data retention policies
  • Dedicated security support
  • Custom BAA for HIPAA compliance
Contact Sales