Back to Home

SOC 2 Compliance

Security & Trust Documentation

BuildFlow Pro is committed to meeting SOC 2 Type II standards. This page outlines our current security controls aligned with the five SOC 2 Trust Service Criteria. We are actively pursuing formal SOC 2 Type II certification.

Overview

SOC 2 (System and Organization Controls 2) is an auditing framework developed by the AICPA that evaluates an organization's controls relevant to security, availability, processing integrity, confidentiality, and privacy. BuildFlow Pro aligns its infrastructure, policies, and procedures to these five Trust Service Criteria.

Security

  • TLS 1.2+ encryption for all data in transit (HTTPS enforced)
  • AES-256 encryption for data at rest
  • Role-based access controls (RBAC) with least-privilege principle
  • Secure OAuth 2.0 authentication for third-party integrations (Stripe, QuickBooks)
  • Automatic session timeout and inactivity logout
  • Regular vulnerability scanning and security patch management
  • Web Application Firewall (WAF) protection
  • DDoS mitigation at the infrastructure level

Availability

  • Cloud-hosted infrastructure with high-availability architecture
  • Automated failover and load balancing
  • Regular automated backups with tested restoration procedures
  • Disaster recovery plan with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO)
  • Uptime monitoring with real-time alerting
  • Scheduled maintenance windows communicated in advance

Processing Integrity

  • Comprehensive audit trails for all entity changes, document signatures, and financial transactions
  • Input validation and data integrity checks across all user-submitted data
  • Automated testing and code review processes before deployments
  • Consistent data processing with logged operations for debugging and forensics
  • Version history for estimates, change orders, and payment schedules

Confidentiality

  • Multi-tenant data isolation ensures no cross-company data leakage
  • Company-scoped access: users only access data within their assigned workspace
  • Subcontractor and client portals provide granular, read-only or scoped access
  • Confidential data (OAuth tokens, API keys) encrypted and never exposed in logs or UI
  • Non-disclosure agreements with employees and contractors
  • Secure disposal of data upon account termination

Privacy

  • Comprehensive Privacy Policy (CCPA, GDPR-aligned) with version tracking and forced re-acceptance
  • Data Processing Agreement (DPA) available for Enterprise customers
  • Cookie consent banner with granular category controls
  • Data subject rights supported: access, correction, deletion, portability, objection
  • Minimal data collection — only what is necessary for service delivery
  • No sale or rental of personal data to third parties
  • Breach Notification Policy with 72-hour notification commitment

Organizational Controls

  • Employee Security Training: All team members receive security awareness training upon onboarding and annually
  • Background Checks: Background verification is performed for employees with access to production systems
  • Access Reviews: Quarterly access reviews ensure appropriate permissions and revoke unnecessary access
  • Incident Response Plan: Documented procedures for identifying, containing, and remediating security incidents
  • Change Management: All code and infrastructure changes go through a review and approval process
  • Vendor Management: Third-party sub-processors are assessed for security posture before engagement

Certification Status

SOC 2 Type II Certification — In Progress

BuildFlow Pro is actively working toward formal SOC 2 Type II certification. Enterprise customers can request our current security controls documentation and audit readiness report.

Related Documents

Contact

For security inquiries, audit requests, or to report a vulnerability: