Skip to main content
Security

How we look after your client data

Buildflow holds client contact details, quotations and your gross margins. This page sets out the controls that are live in the product today. It is maintained by Buildflow CRM Ltd and is not an independent certification, audit report or accreditation. We do not claim ISO 27001, SOC 2 or Cyber Essentials certification, and we do not claim that the product is free of vulnerabilities. Where a control depends on our hosting provider we say so.

Encrypted in transit and at rest

Every page and API call is served over HTTPS only, with HSTS enforced. Database storage and file uploads are encrypted at rest by our hosting provider.

Role-based access inside your workspace

Each staff member is given a role — admin, project manager, estimator, office admin, site supervisor or operative. Roles are stored separately from user profiles and enforced at the database level, not just in the interface, so a user cannot grant themselves extra access.

Workspace isolation

Your company workspace only ever returns your own records. Row-level database policies are applied to every table holding leads, quotations, costs, contracts and client documents.

Sign-in protection

Passwords must be at least 12 characters and are strength-checked at sign-up. Repeated failed sign-in attempts on the same account are rate-limited, and every attempt is recorded for review by your admin.

Client portal links

Client portal access uses single-purpose links that can be given an expiry date and revoked at any time by your admin. Portal visitors only ever see the one project the link was issued for.

Documents kept private

Drawings, quotations, payment schedules and photos are stored in private buckets. Files are served through short-lived signed links to signed-in users only — they are never publicly listable.

Automated security checks

An automated security review runs every hour across access policies, portal access history and sign-in activity, and notifies workspace admins of anything critical. A separate daily job checks data integrity. Workspace admins can see the time and result of the most recent check in the product, so this claim is checkable rather than taken on trust.

Browser hardening

Responses carry a content security policy, HTTPS enforcement, MIME sniffing protection, and referrer and permissions policies.

Backups

The database is backed up automatically by our managed hosting provider. Backup frequency and retention follow that provider's standard schedule for our plan; ask us if you need the current detail in writing.

Shared responsibility

We are responsible for the platform: hosting, encryption, access enforcement, monitoring and backups. You are responsible for who you invite to your workspace, the roles you give them, removing leavers promptly, and the accuracy and lawful basis of the client data you enter. Your clients are responsible for keeping any portal link you send them private.

Sub-processors

Buildflow uses managed cloud hosting for the application and database, a managed email provider for outbound notifications, and — only when you choose to connect them — Google (Gmail and Calendar), your accounting provider and your postal mailing provider. Ask us for the current written list before signing up if you need it for your own records.

Reporting a problem

If you believe you have found a security issue, email support@buildflow.builders with the words “security report” in the subject. Please do not test against other customers’ data. We aim to acknowledge reports within one working day.