Security and governance
What is actually enforced, what proves it, and what we do not claim.
What we enforce, and what checks it
Each statement below is backed by a check we can run against the system, not by a policy document. We list the check by name so the claim can be challenged.
Your company's records are separated from every other company's at the database level, not by application code that could be bypassed.
Checked by:
proof:tenant-boundary (local) and verify:tenant-boundary:post (read-only against production)Row-level security is switched on for every table that holds customer data, and a new table cannot quietly ship without it.
Checked by:
proof:rls-auto-enableThere is no anonymous route to your data. Every database call is made as an authenticated user.
Checked by:
audit:anon-executeWhat a role can do is enforced by the database, so a permission cannot be widened from the browser.
Checked by:
proof:role-boundaryUploaded files and photographs are isolated per company on the same basis as the records that reference them.
Checked by:
proof:storage-isolation
Roles and approvals
Fourteen defined roles, with permissions enforced in the database rather than in the browser. Approvals are a first-class part of the system: items queue to a named approver, authority can be delegated with an end date instead of sharing an account, and the delegation is recorded.
Maker-checker is available and is configured per company. We will not tell you it applies to every sensitive action by default, because that depends on how your company is set up during onboarding - and a control you believe is on when it is off is worse than no control.
Audit trail
Changes are recorded with who made them and when, and for audited records the previous and new values are both kept, so a disputed figure can be answered rather than argued.
Leaving, and getting your data out
Buildem One produces structured exports - Excel, Tally XML and JSON - so your records can leave the system in a form your accountant can use.
Offboarding is deliberately conservative, and we would rather be exact about it. Closing an account suspends access and retains the records; it does not erase them. Our irreversible purge path exists but is intentionally held shut, and we have never run it against a customer. If you need a hard deletion with a certificate, that is a conversation and a written procedure, not a button we press.
The disclosure we owe you
Buildem One is operated by Buildem Construction Solutions, which also supplies construction materials. We disclose this plainly because you should know it. Your commercial data - supplier rates, project costs, stock consumption, client records, billing and margins - is isolated at the database level and is not used for our materials business. We do not use tenant data for pricing, competitive analysis, or sales targeting. Access by our staff is limited to support and operations, is logged, and is available to you on request.
What we do not claim
- We hold no security or compliance certification, and we do not imply that we do. If you need one for procurement, tell us and we will say plainly where we stand.
- We publish no uptime figure we have not contractually committed to.
- We do not describe our security with marketing adjectives.
- We do not claim penetration testing, a bug bounty, or an independent audit. None has been carried out.
- Text-message and WhatsApp one-time codes are registered but not yet live. Sign-in today uses a password with your mobile number as the identifier.