Security
Last updated: September 1, 2026
For security questions or to report a vulnerability: [email protected]
Overview
DataDrivenAEC processes construction drawings, project briefs, and firm data through our paid agent services. This page explains how that data is handled, who sees it, and what controls are in place.
We are a small, bootstrapped company. We do not claim SOC 2 or ISO 27001 certification. What we do claim: a simple, auditable stack with no data resale, clear AI processing disclosure, and the ability to delete your data on request.
01 — Infrastructure and Practices
- All data in transit is encrypted (HTTPS/TLS 1.2+); data at rest is encrypted
- Hosting and file storage run on established cloud providers, encrypted in transit and at rest
- Access to production systems is limited to authorised personnel on a least-privilege basis
- We self-host our website analytics — no cookies, no cross-site tracking, no data sharing with advertising networks, and raw IP addresses are never stored
- Links in cold-outreach emails may be individualized so we can see whether our outreach is relevant to you — see our Privacy Policy for detail
02 — AI Processing
When you submit files for a paid service (drawing review, opportunity research, product research), the content is processed as follows:
| Step | What happens |
|---|---|
| Upload | Your file is stored in Cloudflare R2 and job metadata is stored in Supabase |
| Processing | Workloads run on Amazon Web Services and submitted content may be processed through OpenAI or Anthropic, depending on the service and configured route |
| Delivery | The report is delivered to your email; the uploaded file remains available for limited support and re-processing needs |
| Deletion | Our operational policy is to remove uploaded files within 30 days after delivery, or earlier on request. We do not represent automatic lifecycle enforcement as verified |
What an AI provider sees: The submitted drawing, specification, brief, extracted content, and instructions needed to run the requested analysis.
Training and provider retention: DataDrivenAEC does not use customer files to train models. OpenAI and Anthropic state that commercial/API customer content is not used for model training by default. Standard provider retention can be up to 30 days, and some endpoints, features, legal obligations, or safety exceptions can retain data longer. Zero data retention requires separately verified account controls or agreements.
Sources: OpenAI API data controls and Anthropic commercial data retention
03 — Who Processes Your Data
We share data only with providers acting on our behalf and only as needed to run the Service. Current categories and providers are: file storage (Cloudflare R2), job and account data (Supabase), workload execution (Amazon Web Services), AI processing (OpenAI and Anthropic, depending on route), payment processing (Stripe), and email delivery (Resend and Beehiiv). We never store full card numbers. A current list is available on request at [email protected].
We do not use:
- Google Analytics, Facebook Pixel, or advertising trackers
- Marketing data brokers
- Customer files to train DataDrivenAEC models
04 — Your Data Controls
What you can request at any time:
| Request | How | Timeframe |
|---|---|---|
| Delete your uploaded files | Email [email protected] | Within 7 days |
| Delete your account and all associated data | Email [email protected] | Within 30 days |
| Export your data | Email [email protected] | Within 30 days |
| Receive a copy of your report | Email [email protected] | Within 7 days |
Our operational policy is to remove uploaded files within 30 days of report delivery. Earlier deletion can be requested; storage-level automatic lifecycle enforcement must be independently verified before we describe it as automatic.
05 — What We Do Not Do
- We do not sell your data
- We do not train AI models on your files
- We do not share your files with third parties beyond our AI processing and storage providers, acting on our behalf
- We do not use your uploaded drawings or project data for any purpose other than delivering your purchased report
- We do not store payment card data on our servers
06 — Vulnerability Disclosure
If you discover a security vulnerability, please report it to [email protected].
We will:
- Acknowledge within 5 business days
- Investigate and communicate our findings
- Fix confirmed vulnerabilities promptly
- Credit you in our changelog if you wish
Please do not publicly disclose vulnerabilities before we have had a chance to address them.
07 — Enterprise and Custom Requirements
If your firm requires a data processing agreement (DPA), specific compliance documentation, or custom data handling controls before using our services, contact us at [email protected] and we will work with you directly.
Questions
DataDrivenAEC — Berlin, Germany