Security

Your project data stays protected.

Drawings, site imagery and schedules are sensitive. This page lists exactly what BuildSight does to protect them, and marks anything not yet live.

TopicWhat BuildSight doesStatus
EncryptionData is encrypted at rest (AES-256) and in transit (TLS 1.2 or higher).Live
AuthenticationEmail and password with multi-factor authentication. Enterprise single sign-on (SAML, OIDC).MFA live · SSO on the roadmap
Role-based accessOwner, Admin, Project manager, Contributor and Viewer roles, set per project.Live
Organisation isolationEvery record belongs to one organisation, and isolation is enforced in the database, not only in the application.Live
Audit trailSign-ins, uploads, exports and permission changes are logged and visible to admins.Live
Data retentionAdmins set retention per organisation. Project data is deleted within 30 days of a deletion request.Live
InfrastructureEnterprise cloud infrastructure with encryption and isolation throughout. Initial production infrastructure is hosted on AWS; the application layer is cloud-independent.Live
ComplianceA SOC 2 programme is in planning. We do not claim certifications we do not hold.Roadmap
  • Your data

    Yours, and only yours

    Project data belongs to your organisation. It is never shared with other customers, and you can export all of it at any time.

  • AI and your data

    Answers stay inside your project

    Copilot and analysis read only the data your role can see in that project. Instructions hidden inside documents are treated as content, never followed.

  • Disclosure

    Report a vulnerability

    If you find a security issue, contact the security team through the contact page and we will respond promptly.

See it on your own site.

A live demo on the sample project, then on a batch of your own photos.