Security Overview

Your builds are confidential.
We engineered it that way.

Your project financials, client data, and draw information are isolated to your organization. Database-level access controls mean your records are private to your company.

Multi-Tenant Data Isolation

Complete multi-tenant separation ensures your financial draws, client lists, and bids remain 100% private to your company.

TECHNICAL SAFEGUARD

Database-level Row Level Security (RLS) with Organization ID tenancy checks on every query. Cross-organization data access is blocked at the database layer.

Passwordless Sub Security

Sub-contractors complete field tasks via secure, time-bound magic links, eliminating shared passwords or unauthorized portal access.

TECHNICAL SAFEGUARD

SHA-256 hashed magic tokens with rate-limiting and task-level scope locks. Each token grants access to a single action for a limited time window only.

Bank-Grade Encryption

All data in transit and at rest is protected using industry-standard encryption protocols used by financial institutions.

TECHNICAL SAFEGUARD

TLS 1.3 for all data in transit. AES-256 encryption at rest for documents, portal tokens, and sensitive records. All storage buckets are private with signed URL access only.

Zero Vendor Overshare

We never sell, analyze, or expose custom build budgets or contractor pricing data to third parties. Your competitive data stays yours.

TECHNICAL SAFEGUARD

CCPA/CPRA-aligned data practices with clear data flow documentation. Third-party services receive only what is necessary to deliver their function. No advertising networks. No data brokers.

How we handle your data

What we store

Project data, photos, draw records, team information, and audit logs, all encrypted and isolated to your organization.

Who can access it

Only authenticated members of your organization with the appropriate role. Builtly support staff access data only when you request assistance, with your explicit permission.

What we never do

Sell your data. Train AI on your bids. Share your client lists. Give third parties access to your financial records.

Your team sees only what they need

Builtly enforces role-based access control. Financial data, draw amounts, and contract values are only visible to owners, administrators, and bookkeepers.

RoleFinancial DataDraw AmountsLeads / CRM
Owner Full access Full access Full access
Admin Full access Full access Full access
BookkeeperRead onlyRead only None
Project ManagerProject levelCan submit Full access
Superintendent None None None
Field Crew None None None

Found a security vulnerability?

We take security reports seriously. If you discover a potential security issue in the Builtly platform, please report it responsibly.

Email: legal@builtly.io

Subject: "Security Vulnerability Report"

We will acknowledge your report within 24 hours and work to address valid vulnerabilities promptly. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and address it.

Get started today

Security you can count on.

Role-based access controls, encrypted records, and database-level data isolation. Your data is private to your organization.

Request Founder Access