Security & Data Protection
Your data security is our highest priority. BuilderMate implements enterprise-grade security measures to protect your construction business data.
Data Encryption
In Transit
- 256-bit SSL/TLS encryption for all data transmission
- HTTPS enforced across all BuilderMate services
- Secure API connections to integrations
- Perfect Forward Secrecy (PFS) enabled
At Rest
- AES-256 encryption for database storage
- Encrypted file storage for documents and photos
- Encrypted backups stored in multiple locations
- Encryption keys rotated regularly
Infrastructure Security
- Hosted on AWS with SOC 2 Type II certified data centers
- Geographic redundancy across multiple availability zones
- DDoS protection and web application firewall
- 24/7 infrastructure monitoring and alerting
- Automated security patching
Application Security
- Regular penetration testing by third-party security firms
- Automated vulnerability scanning
- Secure coding practices and code reviews
- Input validation and SQL injection prevention
- XSS and CSRF protection
- Rate limiting and brute force protection
Access Controls
- Role-based access control (RBAC)
- Multi-factor authentication (MFA) available
- Strong password requirements
- Session timeout after inactivity
- IP whitelisting available for enterprise plans
- Audit logs of all data access
Data Backup & Recovery
- Automated daily backups
- Point-in-time recovery up to 30 days
- Backups stored in geographically distributed locations
- Regular disaster recovery testing
- 99.9% uptime SLA
Compliance
- SOC 2 Type II certified (annual audits)
- GDPR compliant for European customers
- CCPA compliant for California residents
- PCI DSS Level 1 compliant (via Stripe)
- HIPAA compliance available for enterprise
Employee Access
- Background checks for all employees
- Security training for all staff
- Least-privilege access principles
- All access logged and monitored
- NDA agreements with all employees
Incident Response
We maintain a comprehensive security incident response plan:
- 24/7 security monitoring and alerting
- Dedicated incident response team
- Notification within 72 hours of confirmed breach
- Post-incident analysis and improvements
Third-Party Security
All third-party services undergo security review:
- AWS (infrastructure hosting)
- Stripe (payment processing - PCI DSS Level 1)
- Twilio (SMS delivery)
- SendGrid (email delivery)
Data Privacy
- We never sell your data
- Data isolation between customer accounts
- You own your data - export anytime
- Data deletion available upon request
- Geographic data residency options
Security Questions?
We're transparent about our security practices. Contact our security team:
Email: [email protected]
For vulnerability reports, please use our responsible disclosure program.
Enterprise Security
Need additional security features? Our Enterprise plan includes:
- Single Sign-On (SSO) via SAML 2.0
- Advanced audit logging
- IP whitelisting
- Custom data retention policies
- Dedicated security support
- Custom BAA for HIPAA compliance