INFORMATION SECURITY POLICY Constructors.AI

Effective Date: 01/01/2026

Constructors.AI is committed to protecting the confidentiality, integrity, and availability of customer data. This Information Security Policy outlines the safeguards and practices implemented to secure information processed by the Constructors.AI platform.

  1. SECURITY PRINCIPLES

Constructors.AI follows three core security principles:

  • Confidentiality – Customer data is accessible only to authorized individuals.
  • Integrity – Data is protected against unauthorized modification.
  • Availability – Systems are designed for reliable uptime and business continuity.
  1. DATA CLASSIFICATION

Data processed by Constructors.AI generally includes:

  • Construction drawings and markup files
  • Estimating quantities and structured outputs
  • Project metadata (job name, location, scope categories)
  • Account and billing information

All customer-uploaded project files are treated as Confidential Business Information.

  1. DATA ENCRYPTION
  2. Data in Transit

All data transmitted between users and the platform is encrypted using:

  • TLS 1.2 or higher

 

 

 

  1. Data at Rest

Customer files and system data are encrypted at rest using:

  • Industry-standard AES-256 encryption (or equivalent cloud-provider encryption standards)
  1. ACCESS CONTROL

Constructors.AI implements role-based access control (RBAC) to ensure:

  • Users can only access their organization’s data.
  • Internal employee access is restricted to authorized personnel.
  • Access is granted based on least-privilege principles.

Multi-factor authentication (MFA) is supported and strongly encouraged.

  1. INTERNAL ACCESS & CONFIDENTIALITY
  • Employees are bound by confidentiality agreements.
  • Administrative access to customer files is limited to:
    • Platform troubleshooting
    • Customer-requested support
  • All administrative actions are logged and auditable.
  1. CLOUD INFRASTRUCTURE

Constructors.AI utilizes reputable cloud infrastructure providers that maintain:

  • SOC 2 compliance (or equivalent)
  • Physical security controls
  • Redundant data centers
  • Disaster recovery systems

Customer data is stored in secure cloud environments with restricted physical and logical access.

  1. DATA SEGREGATION

Customer data is logically segregated by organization.
One customer cannot access another customer’s project files or outputs.

  1. DATA RETENTION & DELETION
  • Customer files are retained during active subscription periods.
  • Upon account termination, customers may request:
    • Data export
    • Permanent deletion
  • Deleted data is removed from active systems within a commercially reasonable timeframe.
  1. INCIDENT RESPONSE

Constructors.AI maintains an incident response plan that includes:

  • Rapid investigation of suspected security events
  • Containment procedures
  • Customer notification where legally required
  • Post-incident review and remediation

Customers will be notified without undue delay if a breach materially affects their data.

  1. MONITORING & AUDITING

We implement:

  • Access logging
  • System activity monitoring
  • Anomaly detection (where available)
  • Periodic review of privileged accounts
  1. THIRD-PARTY RISK MANAGEMENT

Vendors providing hosting, payment processing, or analytics services are evaluated for:

  • Security certifications
  • Data protection practices
  • Contractual confidentiality obligations

Constructors.AI does not share customer files with third parties except as necessary to provide platform functionality.

  1. BUSINESS CONTINUITY

Constructors.AI maintains backup procedures and recovery plans designed to minimize downtime and data loss in the event of system failure.

  1. ENTERPRISE PARTNERSHIPS

If Constructors.AI integrates with a parent or enterprise partner:

  • Full construction drawings are not shared without contractual agreement.
  • Any shared data is limited to approved metadata fields.
  • Data-sharing terms are governed by enterprise agreements.
  1. POLICY UPDATES

This Security Policy may be updated periodically to reflect evolving security practices.