Skip to main content

Effective April 2026

Data Security Statement

This statement summarises how BuiltAI handles client data. It complements our Privacy Policy and the technical and organisational measures detailed in our Master Services Agreement.

1. Hosting and encryption

The BuiltAI platform runs on managed cloud infrastructure with encryption in transit (TLS) and at rest. Files are stored in a private bucket with access mediated by signed URLs and role-based checks.

2. Access controls

  • Authentication via Supabase Auth with strong passwords and support for magic-link sign-in.
  • Role-based authorisation: BuiltAI Admin, Commercial Lead, Delivery Lead, QA Lead, Client Sponsor, Contributor and Reviewer.
  • Client users only ever see their own client account, engagement, tasks and deliverables.
  • Service-role access is restricted to trusted server operations and is audit-logged.

3. Data classification

  • Green: low sensitivity, standard handling.
  • Amber: commercial / operational data, controlled handling and source-backed review.
  • Red: personal, security-sensitive or regulated data - blocked in the MVP. Handled separately under a written secure-route agreement.

4. Audit logging

Major actions - uploads, downloads, QA decisions, approvals, SOWs, AI usage and admin overrides - are recorded in a system audit log with timestamp, actor, target and payload.

5. Sub-processors

We rely on a small set of vetted sub-processors, each bound by a data processing agreement:

  • Supabase - database, authentication and file storage. Our primary data store is hosted in the UK / EU.
  • Vercel - application hosting and delivery.
  • Anthropic - the AI model provider behind our assisted workflows.
  • Resend - transactional email.
  • Sentry - error and performance monitoring.
  • Plausible - privacy-focused, cookieless web analytics.

Our primary database and storage are hosted in the UK / EU. Some providers process data outside the UK; where they do, the transfer is protected by appropriate safeguards (UK adequacy regulations, the UK extension to the EU-US Data Privacy Framework, or the UK International Data Transfer Agreement). We give clients advance notice of any material change to this list.

6. Incident response

In the event of a security incident affecting client data, we will notify the affected client without undue delay and provide the information necessary to fulfil any disclosure obligations.