Security

How we handle your plans, projects and quantities.

This page is maintained by TakeoffAI to answer common security and privacy questions about the product. It describes the controls in the application today — it is not an independent audit or certification.

Controls

Controls in the product today

Authenticated access

Every project, sheet and measurement requires a signed-in account. There is no public read path into project data.

Per-project scoping

Database access rules limit records to the project owner and members explicitly added to that project.

Private plan storage

Uploaded plan PDFs and catalog files live in private storage buckets. Files are served through short-lived signed links, not public URLs.

Encrypted transport

The application and its API are served over HTTPS/TLS, and data is stored on managed infrastructure with encryption at rest.

Least-privilege server code

Privileged credentials are only available to server-side code. They are never shipped to the browser.

Limited outbound email

Email is used for account and product notifications only, sent from our own verified sending domain.

Shared responsibility

Who is responsible for what

Our platform providers

Hosting, managed database, object storage and email delivery run on established third-party infrastructure providers who maintain the underlying platform and its physical and network security.

TakeoffAI

We configure access rules, keep credentials server-side, review changes that touch project data and respond to reported vulnerabilities.

Your team

You control who you invite to a project, the strength of your account credentials and what drawings you upload.

Subprocessors

Services that process data on our behalf

ServicePurpose
SupabaseManaged Postgres database, authentication and file storage
ResendTransactional and notification email delivery
OpenAIAI-assisted detection on drawings you submit for review
Application hostingServing the web application and server endpoints
Disclosure

Reporting a vulnerability

If you believe you've found a security issue, email us with the details and steps to reproduce. We will acknowledge your report and keep you updated while we investigate. Please avoid testing that degrades service or accesses another customer's data.