How we handle your plans, projects and quantities.
This page is maintained by TakeoffAI to answer common security and privacy questions about the product. It describes the controls in the application today — it is not an independent audit or certification.
Controls in the product today
Authenticated access
Every project, sheet and measurement requires a signed-in account. There is no public read path into project data.
Per-project scoping
Database access rules limit records to the project owner and members explicitly added to that project.
Private plan storage
Uploaded plan PDFs and catalog files live in private storage buckets. Files are served through short-lived signed links, not public URLs.
Encrypted transport
The application and its API are served over HTTPS/TLS, and data is stored on managed infrastructure with encryption at rest.
Least-privilege server code
Privileged credentials are only available to server-side code. They are never shipped to the browser.
Limited outbound email
Email is used for account and product notifications only, sent from our own verified sending domain.
Who is responsible for what
Our platform providers
Hosting, managed database, object storage and email delivery run on established third-party infrastructure providers who maintain the underlying platform and its physical and network security.
TakeoffAI
We configure access rules, keep credentials server-side, review changes that touch project data and respond to reported vulnerabilities.
Your team
You control who you invite to a project, the strength of your account credentials and what drawings you upload.
Services that process data on our behalf
| Service | Purpose |
|---|---|
| Supabase | Managed Postgres database, authentication and file storage |
| Resend | Transactional and notification email delivery |
| OpenAI | AI-assisted detection on drawings you submit for review |
| Application hosting | Serving the web application and server endpoints |
Reporting a vulnerability
If you believe you've found a security issue, email us with the details and steps to reproduce. We will acknowledge your report and keep you updated while we investigate. Please avoid testing that degrades service or accesses another customer's data.