Security
Security is fundamental to how Builda is designed, operated, and maintained.
Builda LLC (“Builda,” “we,” “us,” or “our”) maintains administrative, technical, organizational, and physical safeguards designed to protect Customer Data and the systems used to provide Builda.
Our security program is based on protecting the confidentiality, integrity, and availability of information and is designed to evolve with our platform, applicable legal requirements, recognized security standards, and the changing threat landscape.
Data Security
Builda applies security controls throughout the lifecycle of Customer Data.
Encryption
Builda protects Customer Data using encryption in transit and at rest using industry-standard technologies appropriate to the systems and information involved.
Encryption keys, credentials, secrets, and other sensitive authentication information are protected through access controls and restricted according to the principle of least privilege.
Data Segregation
Customer Data is logically separated to prevent unauthorized access between customer organizations.
Builda maintains separation between production and non-production environments. Production Customer Data is not used in development or testing except where specifically authorized, appropriately protected, and permitted by applicable law and contractual requirements.
Data Integrity
Builda maintains controls designed to protect Customer Data against unauthorized or improper alteration, destruction, or loss.
Backups and Recovery
Builda maintains backup, restoration, and recovery procedures designed to protect against accidental deletion, corruption, infrastructure failures, security incidents, and other disruptions.
Backups containing Customer Data are protected using security controls appropriate to the information they contain. Backup and recovery procedures are reviewed and tested periodically.
Access Control
Access to Builda systems and Customer Data is restricted according to legitimate business need and the principle of least privilege.
Builda maintains access controls designed to limit access to authorized personnel and systems. These controls include authentication requirements, appropriate administrative privilege restrictions, access reviews, and revocation or modification of access when it is no longer required.
Multi-factor authentication is required for sensitive administrative and internal systems where appropriate and supported.
Access to Customer Data by Builda personnel is limited to authorized purposes, such as providing customer support, maintaining and securing the Services, investigating incidents, satisfying legal obligations, or otherwise performing legitimate functions necessary to provide the Services.
Logging and Monitoring
Builda maintains logging and monitoring controls designed to detect unauthorized access, suspicious activity, security events, and operational anomalies.
Security-relevant activity may include authentication events, administrative actions, access events, system activity, configuration changes, and other events appropriate to the applicable system.
Logs may be used for security monitoring, investigation, incident response, auditing, troubleshooting, and improvement of Builda’s security program.
Infrastructure and Network Security
Builda uses layered security controls designed to reduce the risk of unauthorized access, misuse, compromise, disruption, or loss.
Infrastructure and network safeguards are selected based on risk and may include network access controls, firewalls, application security controls, threat detection, vulnerability scanning, monitoring and alerting, restricted administrative access, encryption, configuration management, endpoint protections, redundancy, and denial-of-service protections.
Where Builda relies on cloud infrastructure or other service providers, applicable physical data-center security is provided through those providers and evaluated as part of Builda’s third-party risk management practices.
Secure Software Development
Security is incorporated into Builda’s software development lifecycle.
Builda maintains development practices designed to identify and reduce security risks throughout the design, development, testing, deployment, and maintenance of the Services.
These practices include security consideration during system design, source-code access controls, code review, change management, dependency and vulnerability management, security testing appropriate to risk, separation of production and non-production environments, and additional review of security-sensitive functionality.
Vulnerability Management
Builda maintains processes to identify, assess, prioritize, remediate, and monitor security vulnerabilities.
Vulnerabilities are evaluated based on factors including severity, exploitability, exposure, affected systems, and potential impact. Remediation priorities and timelines are determined based on risk.
Builda may use automated scanning, dependency monitoring, security testing, code analysis, infrastructure assessments, penetration testing, third-party assessments, and responsible vulnerability reporting as part of this program.
Incident Response
Builda maintains an incident response process designed to support preparation, identification, containment, investigation, remediation, recovery, and post-incident review.
Potential security incidents are evaluated based on their nature, severity, scope, and potential impact.
Where a security incident or personal data breach triggers notification obligations, Builda will provide notifications to customers, regulators, individuals, or other parties as required by applicable law and applicable contractual obligations.
Following a significant incident, Builda may perform root-cause analysis, document corrective actions, and update security controls or procedures as appropriate.
Business Continuity and Disaster Recovery
Builda maintains business continuity and disaster recovery practices designed to support the availability and recoverability of the Services.
These practices address risks including infrastructure failures, data loss, cybersecurity incidents, service-provider disruptions, and other events that could materially interfere with normal operations.
Recovery procedures, backups, system dependencies, and continuity controls are periodically reviewed and tested according to risk.
Personnel Security
Personnel with access to Builda systems or information are subject to security responsibilities appropriate to their roles.
Builda maintains personnel security measures that may include confidentiality obligations, security policies, security awareness training, access restrictions, authentication controls, device security requirements, and procedures for modifying or terminating system access when responsibilities change or employment or engagement ends.
Additional safeguards may apply to personnel with privileged or sensitive access.
Endpoint Security
Devices used to administer or access sensitive Builda systems are subject to security safeguards appropriate to their access level and risk.
These safeguards may include device encryption, screen locking, security updates, endpoint protection, malware detection, software controls, authentication requirements, and device-management capabilities.
Third-Party and Subprocessor Security
Builda uses third-party service providers and subprocessors where necessary to provide and operate the Services.
Builda evaluates material providers according to the nature of the services they provide, the information they may access, and the risks associated with that access.
Where appropriate, contracts with service providers include security, confidentiality, privacy, and data-protection obligations.
Third-party access to Builda systems and information is limited according to legitimate business need and applicable security requirements.
Additional information concerning subprocessors and processing of personal data may be provided through Builda’s Privacy Policy, Data Processing Addendum, subprocessor documentation, or other applicable agreements.
Data Retention and Secure Disposal
Builda retains Customer Data for as long as reasonably necessary to provide the Services, fulfill contractual obligations, comply with applicable law, resolve disputes, maintain security, and enforce applicable agreements.
When information is no longer required and no legal or legitimate business reason requires its retention, Builda uses processes designed to securely delete, destroy, anonymize, or otherwise render that information inaccessible in accordance with applicable retention requirements.
Customers may request deletion of Customer Data subject to applicable law, contractual requirements, retention obligations, and technical limitations.
Privacy and Data Protection
Builda maintains privacy and data-governance practices designed to support appropriate handling of personal information.
Builda considers principles such as data minimization, purpose limitation, access control, retention, deletion, security, vendor management, incident response, and appropriate safeguards for international transfers where applicable.
Additional information about Builda’s collection, use, disclosure, retention, and other processing of personal information is provided in Builda’s Privacy Policy and, where applicable, its Data Processing Addendum.
Artificial Intelligence Governance
Where Builda develops, provides, or uses artificial intelligence systems, Builda incorporates AI-related risks into its broader governance, security, privacy, and risk-management processes.
Depending on the system, purpose, and risk involved, these processes may address AI system governance, risk assessment, data governance, security, privacy, access control, human oversight, third-party AI providers, testing, monitoring, documentation, accountability, incident management, and ongoing evaluation.
Builda’s AI governance practices are intended to evolve with applicable laws, recognized standards, industry practices, and changes in the AI systems Builda develops or uses.
HIPAA and Protected Health Information
Builda supports the processing of Protected Health Information (“PHI”) only where Builda has expressly agreed in writing to do so and where the applicable Services and configuration have been approved for that purpose.
Where Builda acts as a business associate under the Health Insurance Portability and Accountability Act (“HIPAA”), Builda and the applicable customer must enter into a Business Associate Agreement (“BAA”) as required by law.
HIPAA eligibility does not necessarily extend to every Builda feature, integration, third-party service, or configuration. Customers subject to HIPAA are responsible for using only approved Services and configurations for PHI and for satisfying their own obligations under applicable law.
Security and Compliance Framework
Builda’s security and compliance program is developed with reference to recognized security, privacy, and risk-management frameworks applicable to the Services and Builda’s business.
SOC 2
Builda’s security program is designed with consideration for applicable AICPA Trust Services Criteria, including controls relevant to security and any other criteria included within the applicable scope.
A SOC 2 Type II examination, when applicable, evaluates controls included within the examination over a defined period. Any statement that Builda has completed a SOC 2 examination applies only when expressly stated by Builda and is limited to the scope, systems, criteria, and examination period identified in the applicable independent auditor’s report.
ISO/IEC 27001
Builda’s information security management practices are designed with consideration for the risk-based information security principles and management-system requirements of ISO/IEC 27001.
Any representation that Builda is ISO/IEC 27001 certified applies only if Builda has received an applicable certification and only to the organizational and technical scope identified on that certificate.
ISO/IEC 42001
Builda’s AI governance program is designed with consideration for the management-system principles of ISO/IEC 42001 for the responsible development, provision, or use of artificial intelligence systems.
Any representation that Builda is ISO/IEC 42001 certified applies only if Builda has received an applicable certification and only to the scope identified on that certificate.
HIPAA
Where Builda is subject to HIPAA as a business associate, Builda maintains safeguards intended to satisfy applicable administrative, physical, and technical requirements of the HIPAA Rules and the obligations contained in the applicable BAA.
HIPAA applicability and eligibility depend on Builda’s role, the applicable Services, customer configuration, integrations, and contractual relationship.
GDPR
Where the General Data Protection Regulation (“GDPR”) applies to Builda’s processing of personal data, Builda maintains technical and organizational measures designed to provide a level of security appropriate to the applicable risk.
Where Builda processes personal data on behalf of a customer as a processor, applicable processing obligations may be addressed through a Data Processing Addendum or other written agreement.
Builda’s role and obligations under the GDPR depend on the circumstances of the applicable processing activity.
United States Privacy and Data Security
Builda maintains security and privacy practices designed to address applicable United States federal and state privacy, consumer-protection, data-security, and breach-notification requirements.
There is no single security law applicable to every U.S. business. The specific requirements applicable to Builda or a customer depend on factors such as the information processed, the applicable jurisdiction, the industry involved, and Builda’s role in processing the information.
Customer Responsibilities
Security is a shared responsibility. Customers are responsible for configuring and using Builda appropriately, including controlling authorized users and permissions, protecting credentials, enabling available security features, maintaining secure devices, reviewing integrations and third-party applications, promptly removing access that is no longer required, complying with laws applicable to their use of the Services, and notifying Builda of suspected unauthorized access or security incidents.
Continuous Improvement
Builda periodically evaluates its security program and may update its controls, technologies, policies, procedures, and practices in response to changes in the Services, identified risks, legal requirements, recognized security standards, technology, and the threat landscape.
Reporting Security Concerns
If you believe you have discovered a security vulnerability, unauthorized access, or another security issue involving Builda, contact:
support@buildaos.com
Please provide sufficient information for Builda to understand and investigate the issue.
Security researchers must not intentionally access, modify, destroy, retain, or disclose data belonging to another person or organization, disrupt the Services, or conduct testing that violates applicable law.
Security and Compliance Documentation
Builda may make additional security and compliance documentation available to customers, prospective customers, auditors, regulators, or other authorized parties where appropriate.
Depending on availability, applicable scope, and confidentiality requirements, this documentation may include security questionnaires, policies, audit reports, certifications, penetration testing summaries, Data Processing Addenda, Business Associate Agreements, subprocessor information, or other security and compliance materials.
About This Page
This page provides a general overview of Builda LLC’s security practices.
It does not modify an agreement with Builda, create a warranty or guarantee, or expand Builda’s contractual obligations unless expressly incorporated into a written agreement.
Specific security, privacy, compliance, regulatory, and contractual obligations are governed by applicable law and the applicable agreement between Builda and the customer.
Builda may update this page as its Services, security practices, technologies, certifications, and legal obligations evolve.