Skip to content
§00 Security & Compliance

Audited. Measured. Field-proven.

SOC 2 Type II controls continuously attested since 2021, 99.97% uptime across the last 36 months, and 2.1 million monthly field events processed without a single incident — all available for review under NDA before your security team signs off.

Used on 11,400+ active projects across 47 U.S. states and 19 countries · Trusted by 9 of the ENR Top 400 contractors.

§01 Certifications & Tenure

Every audit mark, on a single spec sheet.

The certifications your procurement team scans for — listed the way a stamp-block on a drawing sheet lists them, with the year it was first issued.

Type II Attested

Independent audit by a Big Four firm. Security, Availability, and Confidentiality trust services criteria — re-attested quarterly, with the latest letter dated Q3 2024.

Held continuously since 2021.

EU Data Protection Ready

Standard Contractual Clauses in place, EU-Frankfurt data residency available on the Enterprise tier, and a named Data Protection Officer reachable at [email protected].

In production since 2022.

ISO 27001:2022 Aligned

All 93 Annex A controls mapped in our Statement of Applicability. Formal certification tracking has read-out 2025; interim alignment confirmed against the 2022 control set.

Controls in place since 2022.

Encryption Posture

AES-256 at rest across all object stores and Postgres volumes. TLS 1.3 in transit, HSTS preloaded, certificate transparency monitored. Customer-managed keys via AWS KMS on the Enterprise tier.

Penetration tested annually by Curia Labs.

§02 What SOC 2 Type II Means On Site

A trust-services report, translated into the language of a Tuesday morning jobsite.

"SOC 2" is the audit credential a CFO recognizes; "what does it actually do for our project" is what your project executive will ask on the demo call. Here is the operational translation.

  • 01

    Continuous access logging on every drawing revision

    Every drawing upload, redline, and markup is tied to a named user, a session, an IP range, and a timestamp — logged to a write-once bucket with 7-year retention. If a subcontractor opens Sheet A-301 from a café in Cleveland at 06:42, your IT team can tell you exactly what was viewed and exported.

  • 02

    Change-management gates on every configuration push

    No code reaches production without a peer-reviewed merge, an automated test pass, and a documented approver. The same control covers your tenant configuration — workflow edits, permission changes, and integration token rotations are recorded for the audit window.

  • 03

    Quarterly attestation refreshes

    Our Type II window never closes — a Big Four firm tests controls continuously and re-issues the report every quarter. The letter on file is never older than 90 days, which is the answer your security reviewer wants before signing.

  • 04

    Annual third-party penetration test

    The most recent test was completed on 2024-11-08 by Curia Labs, covering web app, API (120+ endpoints), and infrastructure. Critical findings SLA: 14 days to remediate or document compensating control — and the SLA itself has held on every prior cycle.

§03 Compliance Frameworks

Mapped against the questionnaires your owner clients send.

Four frameworks, one row each, with the controls and the documents that satisfy a procurement reviewer’s first pass.

SOC 2 2021 →

Security · Availability · Confidentiality

Type II attestation covering all three TSCs. Continuous monitoring, annual penetration test, quarterly letters on file.

  • Logical access
  • Change mgmt
  • Incident response
  • Disaster recovery
GDPR 2022 →

EU Data Subject Rights

SCCs in place, EU-Frankfurt residency available, 30-day DSAR turnaround SLA, and a contracted DPO.

  • SCCs
  • DSAR
  • Right to erasure
  • Breach notification <72h
ISO 27001:2022

Annex A Control Set

All 93 Annex A controls mapped in our Statement of Applicability. Formal certification tracking through 2025.

  • A.5–A.8 Org controls
  • A.8 Asset mgmt
  • Cryptography
  • Supplier relationships
NIST CSF 2.0

Cybersecurity Framework

Mapped to Identify, Protect, Detect, Respond, Recover, and the new Govern function. Aligned with federal procurement standards.

  • Identify
  • Protect
  • Detect
  • Respond · Recover · Govern
§04 Pre-Demo Checklist

Yes — it’s ready for your security review.

Most procurement questionnaires land before the demo call. Here are the answers, in the order they tend to come up, so the call starts with architecture instead of paperwork.

Where does data live?
US-East (Virginia) by default, with EU-Frankfurt available for tenants whose project work crosses European jobsites. Region is selected at tenant provisioning and pinned for the life of the workspace.
Do you support customer-managed keys?
Yes — on the Enterprise tier, encryption keys are held in your AWS KMS instance. Key rotation, revocation, and audit logs are returned to your CloudTrail.
How is SSO handled?
SAML 2.0 and OIDC against any IdP — Okta, Microsoft Entra, Google Workspace, Ping, JumpCloud. SCIM provisioning ships standard. Just-in-time deprovisioning closes the access gap the day a foreman moves to a new project.
What happens if a subcontractor’s laptop is stolen?
An administrator can revoke a session in under 60 seconds from the audit console. The next API call from that device is refused at the edge, and the bearer token is added to a deny list within the 14-day vulnerability SLA.
Can you sign our DPA, BAA, or custom security addendum?
Our standard DPA, CCPA addendum, and SOC 2-aligned security exhibit are turnkey. Custom redlines on request — counterparty contracts are reviewed by outside counsel with a 5-business-day turnaround.
§05 Next Step

Two ways off this page.

Pick the one that matches your role: a live demo with the security brief included, or the public uptime artifact you can hand to procurement today.

A // DEMO For the buyer

Book a 30-minute demo with a solutions engineer.

Walk through your project workflows with someone who has run a $40M build. The SOC 2 Type II report, the latest penetration-test summary, and the uptime PDF are bundled into the calendar invite under NDA.

Book a Demo → Avg. first response: 4h 12m · Mon–Fri 7am–7pm CT
B // ARTIFACT For the reviewer

Download the public 36-month uptime report.

The same uptime record our status page publishes, packaged as a printable PDF. Shareable with anyone on your procurement checklist — no NDA required.

Request Uptime PDF Window covered: Nov 2021 – Nov 2024 · 99.97%