Security & Trust
Your company's data, isolated by design
SmartBuildOS is a multi-tenant platform built the way a multi-tenant platform should be: every company's data is separated at the database layer, and every role sees exactly what it should — no more, no less.
How it's built
Security is an architecture, not a checkbox
These aren't settings you have to turn on. They're how the platform is constructed.
Company isolation in the database
Every record belongs to a company, and row-level security enforces that boundary on every query — not just in the interface. One tenant can never read another's data.
Role, location & row-level access
Owners, managers, technicians, purchasing, finance, and clients each see a different slice of the system, scoped by role, assigned location, and record ownership.
Client-safe by default
Client-facing proposals and the portal hide internal notes, supplier cost, margins, and profit analysis. Your customers see a clean quote; your numbers stay yours.
Encrypted in transit and at rest
Built on managed PostgreSQL with TLS on every connection and encryption at rest. Your operational data is protected end to end.
Least-privilege by design
Every action is permission-checked the same way its data is. There are no privileged back doors through the API that skip the checks the interface enforces.
Traceable history
Projects, jobs, and statuses carry their own change history, so you can see who moved what and when — the record of the work, not just its current state.
Straight talk
What we don't do
The most honest thing a security page can include is the list of things it refuses to claim.
- We don't sell or share your company data.
- We don't claim certifications we don't hold — security here is an architecture decision, enforced in the database.
- We don't hide cost and margin from your team, only from your clients — you always see the full picture.
- We don't bolt permissions onto the UI; access is scoped at the data layer, so it holds even outside the app.
Questions from your IT or security team?
We’re happy to walk through the tenancy model, permission scoping, data handling, and hosting in detail. Bring your questionnaire.