Trust centre

Security at BuildPilot AI

A practical overview of the safeguards used to protect accounts, private workspaces and construction data.

Last updated: 13 August 2026

Layered security

BuildPilot uses multiple controls rather than relying on a single defensive measure. These include authenticated access, tenant-scoped database queries, rate limiting, audit records, secure transport and restricted file handling.

Authentication and sessions

Private features require an authenticated account. Passwords are hashed, sessions are signed and sensitive actions are checked against the current user and business workspace.

Workspace isolation

Customer records are associated with a business workspace. Tender, estimate, rate-library and document operations are scoped to that workspace to reduce the risk of one customer accessing another customer's information.

Rate limiting and abuse protection

Production rate limiting uses a shared Redis-backed store where configured. BuildPilot has verified that repeated requests can be blocked with HTTP 429 responses. Limits are applied to sensitive and expensive actions such as authentication, AI analysis and file operations.

Uploaded files

File uploads are restricted by size and supported type. File metadata and signatures should be validated, and access to stored tender documents is checked against the requesting workspace. Customers should not upload malware, executable files or information they are not authorised to process.

Payments

Stripe processes card payments. BuildPilot does not intentionally store complete payment-card numbers or card security codes.

AI safeguards

Commercial outputs remain subject to human review. BuildPilot is designed not to invent unknown rates or silently apply suggested pricing. Tender analysis, estimate matching and customer communications should be reviewed before use.

Incident response

Suspected personal-data breaches are contained, risk-assessed and recorded. Where a breach is likely to result in a risk to people, the operator follows the applicable ICO notification timetable and communicates with affected people where the risk is high. See the incident-response overview.

Reporting a concern

Report suspected security issues privately to admin@buildpilotai.co.uk. Do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate.

Important limitation

No online service can guarantee that incidents will never occur. BuildPilot continuously develops its controls and may update this overview as the platform evolves.