Skip to main content
Security

How we look after your client data

Buildflow holds client contact details, quotations and your gross margins. This page sets out the controls that are live in the product today. It is maintained by Daryl Edwards trading as Buildflow and is not an independent certification, audit report or accreditation. We do not claim ISO 27001, SOC 2 or Cyber Essentials certification, and we do not claim that the product is free of vulnerabilities. Where a control depends on our hosting provider we say so.

Encrypted in transit and at rest

Every page and API call is served over HTTPS only, with HSTS enforced. Database storage and file uploads are encrypted at rest by our hosting provider.

Role-based access inside your workspace

Each staff member is given a role — admin, project manager, estimator, office admin, site supervisor or operative. Roles are stored separately from user profiles and enforced at the database level, not just in the interface, so a user cannot grant themselves extra access.

Workspace isolation

Your company workspace only ever returns your own records. Row-level database policies are applied to every table holding leads, quotations, costs, contracts and client documents.

Two-factor and passkeys

Every account can add authenticator-app two-factor sign-in, passkeys (Face ID, Touch ID or a security key) and single-use backup codes. Admins can make two-factor mandatory for the whole workspace or for manager and director roles, review trusted devices and remove them remotely.

Sign-in protection

Passwords must be at least 12 characters and are strength-checked at sign-up. Repeated failed sign-in attempts on the same account are rate-limited, and every attempt is recorded for review by your admin.

Client portal links

A portal link on its own is not enough to open a project. The visitor must also sign in with the email address the project was shared with, and every attempt — allowed or refused — is written to an access log. Links are single-purpose, can be given an expiry date and can be revoked at any time by your admin. A visitor only ever sees the one project the link was issued for, so a forwarded link does not give the new holder access.

Documents kept private

Drawings, quotations, payment schedules and photos are stored in private buckets. Files are served through short-lived signed links. Only signed-in staff in your workspace, and client-portal visitors signed in with the invited email address for that one project, can open them — they are never publicly listable.

Automated security checks

An automated security review is scheduled to run across access policies, portal access history and sign-in activity, and notifies workspace admins of anything critical. A separate daily job checks data integrity. Rather than ask you to take the schedule on trust, workspace admins can see the time and result of the most recent completed run inside the product — if no run has completed yet, it says so.

Browser hardening

Responses carry a content security policy, HTTPS enforcement, MIME sniffing protection, and referrer and permissions policies.

Backups

The database is backed up automatically by our managed hosting provider. Backup frequency and retention follow that provider's standard schedule for our plan; ask us if you need the current detail in writing.

Backups, recovery and availability

Our position as it stands today, including where we have not yet made a commitment.

Backup frequency
Automated by our managed hosting provider on that provider's standard schedule for our plan. We have not independently verified the interval, so we do not publish one as a commitment.
Retention
Set and controlled by the same provider for our current plan. We do not operate a separate, longer-retained backup copy of our own.
Restore testing
We have not completed and published a documented full restore test. When we do, the date and result will be published here.
Recovery time and recovery point objective
None committed. We will not publish an RTO or RPO figure we cannot evidence. If your procurement needs committed figures, ask us before you sign and we will confirm in writing what our provider guarantees for our current plan.
Availability commitment
No contractual uptime percentage or service credit scheme today. The service is monitored and we notify workspace administrators of unplanned outages.
What you can rely on now
Your own copy: leads, quotations, projects, costs, contacts and audit logs export to CSV, and documents, photos and PDFs download as a single file, at any time while your subscription is live. That export is the recovery route entirely within your control.

Questions buyers ask before signing

How is our data backed up, and how quickly could you recover it?
The application database is backed up automatically by our managed hosting provider on that provider's standard schedule for our plan. Backup frequency, retention and restore options are controlled by that provider for the current plan, and we do not have independent evidence that point-in-time recovery or replicated object storage are enabled. We have not published a contractual recovery time or recovery point objective, and we will not invent one. If you need committed figures or the current entitlement confirmed in writing, ask us and we will confirm what our provider guarantees for our current plan before you sign.
Can we get our data out, and what happens if we leave?
Yes. Leads, quotations, projects, variations and financial records can be exported to CSV from the application at any time while your subscription is active, and documents can be downloaded from the files area. After cancellation your workspace stays available for export for 30 days. After that the workspace and its contents are deleted, except security and billing records we are required to keep for up to six years.
Can you delete specific records on request?
Yes. You can delete records yourself in the application, and you can ask us to erase a named individual's personal data to meet a subject access or erasure request. Deletions remove the record from live surfaces immediately and from backups as those backups age out of the provider's retention window; we cannot surgically edit historic backups.
What happens if there is a breach?
We investigate immediately, contain the issue, and notify affected customers without undue delay. Where we act as your processor we will notify you within 72 hours of becoming aware of a personal data breach, with the facts we hold at that point, and keep you updated as the investigation continues. Our data processing agreement records this commitment. We also publish a security contact and a vulnerability reporting route, and we acknowledge reports within one working day.
Where is our data held?
The application database and your uploaded files are hosted in the UK/EU. Some services necessarily operate outside that region: the site is served through a global edge network, outbound email is sent through your connected Google account, optional SMS is sent from the United States, and the optional AI features send the selected content to providers processing in the United States. Those transfers rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses. Not connecting Google and not using the AI features reduces those optional transfers, but core infrastructure and security providers may still process data internationally under those safeguards.
Who inside our company can see costs and margins?
Access is role-based and enforced in the database, not just hidden in the interface. Costs, margins and financial reporting are limited to senior roles; site supervisors and operatives see the job information they need and not the money. Your workspace administrator sets each person's role and removes leavers.

Shared responsibility

We are responsible for the platform: hosting, encryption, access enforcement, monitoring and backups. You are responsible for who you invite to your workspace, the roles you give them, removing leavers promptly, and the accuracy and lawful basis of the client data you enter. Your clients are responsible for keeping any portal link you send them private.

Sub-processors

We publish a versioned list naming every provider that may process data on our behalf, what it does, where processing happens and whether it is optional. See the sub-processors list, and download our standard data processing agreement if you need it for your own records.

Reporting a problem

Use the form below, or email support@buildflow.builders with the words “security report” in the subject. Please do not test against other customers’ data. We acknowledge reports within one working day (Monday to Friday, UK time) — reports sent through the form get a reference and a stored acknowledgement deadline, and you can check the actual acknowledgement timestamp at any time, so the promise is checkable rather than taken on trust.

Report a security issue

We log the report with a reference and an acknowledgement deadline of one working day (Monday to Friday, UK time). You can check the real acknowledgement time here.

Check acknowledgement status

Enter your reference and the email you reported from to see when we acknowledged it.