Privacy and security
How bldrAgent protects your data, what security practices we follow, and where your data is stored.
Our commitment to security
bldrAgent is built with security at its core. We apply modern best practices to protect your data and your users' data at every layer.
Data encryption
| Layer | Protection |
|---|---|
| Data in transit | TLS 1.2+ for all connections |
| Data at rest | AES-256 encryption for all databases and file storage |
| Passwords | bcrypt hashing (never stored in plaintext) |
| Secrets / API keys | AES-256 encrypted, write-only access |
| Database backups | Encrypted before transmission and at rest |
Infrastructure security
- Hosted on AWS with VPC isolation
- All services run in private subnets — only the load balancer is publicly accessible
- Database servers are not accessible from the public internet
- Automated vulnerability scanning on all infrastructure components
- Dependency security patches applied within 24–72 hours of disclosure
Application security
- SQL injection — Prisma ORM with parameterised queries; no raw SQL from user input
- XSS — all user content is sanitised before rendering
- CSRF — token-based CSRF protection on all state-changing endpoints
- Rate limiting — all authentication and API endpoints are rate-limited
- Input validation — all API inputs are validated with Zod schemas
- Security headers — HSTS, CSP, X-Frame-Options, and referrer policies applied globally
Data residency
Your workspace data is stored in the AWS region you selected when creating your workspace:
- US East (N. Virginia)
- EU West (Ireland)
- Asia Pacific (Sydney)
App databases, media files, and backups all reside in your chosen region.
GDPR compliance
bldrAgent is GDPR compliant for European users:
- You are the data controller for your app's user data
- bldrAgent acts as a data processor under a Data Processing Agreement (DPA)
- Request a DPA at legal@bldr.app
- Right to erasure requests are supported — see Deleting user data
SOC 2 and certifications
bldrAgent is currently undergoing SOC 2 Type II certification. Enterprise customers can request our current security report and questionnaire responses from security@bldr.app.
Responsible disclosure
If you discover a security vulnerability in bldrAgent, please report it to security@bldr.app. We respond within 48 hours and have a responsible disclosure policy with credit for valid reports.
