Security
Last updated September 30, 2026
Template: have a lawyer review before launch
This page is a starting draft written for BldgHelm's pilot. It is not legal advice and has not been reviewed by a lawyer.
Universities trust BldgHelm with the records of their campuses. This page describes how that data is protected.
Keeping customers apart
- Every record belongs to one organization, and the database itself enforces who may read or change it (Postgres row-level security on every table), not just the screens.
- Roles (Owner Admin, Facilities Manager, Technician, Viewer) are checked by the database. Cost figures, warranties and billing live in separate tables that only the allowed roles can read.
- Contractors see only the work assigned to their company, only for owners that invited them, and never other contractors or owners.
- Automated tests prove that one organization cannot read another's data and that a contractor cannot see unassigned work; they run on every change.
Data protection
- All traffic is encrypted with HTTPS (HSTS enforced). The database and file storage are encrypted at rest by our provider, Supabase.
- Photos and documents are stored in private buckets and shown only through signed links that expire.
- Nothing is hard-deleted: records are archived, and an audit log records who created, changed or archived what, and when, with the before and after values.
- Daily database backups; point-in-time recovery is switched on once customers are paying.
- Card and bank details are handled by Stripe (PCI DSS Level 1); BldgHelm never sees them.
Application security
- A strict Content-Security-Policy with per-request nonces, protection against framing (clickjacking) and other standard security headers.
- Rate limits on invitations, exports, AI estimates, billing actions and the public repair form, which also uses Cloudflare Turnstile and a honeypot against spam.
- Secrets live in environment variables, never in code. The service key that bypasses row-level security is used only by trusted server jobs.
- Error reports are scrubbed of emails, phone numbers, tracking codes and credentials before they leave the app.
Accessibility
BldgHelm targets WCAG 2.1 AA. A VPAT (accessibility conformance report) is available on request.
Reporting a problem
If you believe you have found a security issue, please contact BldgHelm at the address on your order form. We will respond promptly and will not take action against good-faith research.