BuildFlow Pro is committed to meeting SOC 2 Type II standards. This page outlines our current security controls aligned with the five SOC 2 Trust Service Criteria. We are actively pursuing formal SOC 2 Type II certification.
Overview
SOC 2 (System and Organization Controls 2) is an auditing framework developed by the AICPA that evaluates an organization's controls relevant to security, availability, processing integrity, confidentiality, and privacy. BuildFlow Pro aligns its infrastructure, policies, and procedures to these five Trust Service Criteria.
Security
TLS 1.2+ encryption for all data in transit (HTTPS enforced)
AES-256 encryption for data at rest
Role-based access controls (RBAC) with least-privilege principle
Secure OAuth 2.0 authentication for third-party integrations (Stripe, QuickBooks)
Automatic session timeout and inactivity logout
Regular vulnerability scanning and security patch management
Web Application Firewall (WAF) protection
DDoS mitigation at the infrastructure level
Availability
Cloud-hosted infrastructure with high-availability architecture
Automated failover and load balancing
Regular automated backups with tested restoration procedures
Disaster recovery plan with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO)
Uptime monitoring with real-time alerting
Scheduled maintenance windows communicated in advance
Processing Integrity
Comprehensive audit trails for all entity changes, document signatures, and financial transactions
Input validation and data integrity checks across all user-submitted data
Automated testing and code review processes before deployments
Consistent data processing with logged operations for debugging and forensics
Version history for estimates, change orders, and payment schedules
Confidentiality
Multi-tenant data isolation ensures no cross-company data leakage
Company-scoped access: users only access data within their assigned workspace
Subcontractor and client portals provide granular, read-only or scoped access
Confidential data (OAuth tokens, API keys) encrypted and never exposed in logs or UI
Non-disclosure agreements with employees and contractors
Secure disposal of data upon account termination
Privacy
Comprehensive Privacy Policy (CCPA, GDPR-aligned) with version tracking and forced re-acceptance
Data Processing Agreement (DPA) available for Enterprise customers
Cookie consent banner with granular category controls
Data subject rights supported: access, correction, deletion, portability, objection
Minimal data collection — only what is necessary for service delivery
No sale or rental of personal data to third parties
Breach Notification Policy with 72-hour notification commitment
Organizational Controls
Employee Security Training: All team members receive security awareness training upon onboarding and annually
Background Checks: Background verification is performed for employees with access to production systems
Incident Response Plan: Documented procedures for identifying, containing, and remediating security incidents
Change Management: All code and infrastructure changes go through a review and approval process
Vendor Management: Third-party sub-processors are assessed for security posture before engagement
Certification Status
SOC 2 Type II Certification — In Progress
BuildFlow Pro is actively working toward formal SOC 2 Type II certification. Enterprise customers can request our current security controls documentation and audit readiness report.