SECURITY YOUR PROJECT RECORD, PROTECTED

Built to be the system
of record — and trusted like one.

Construction documents settle disputes worth millions. Brixdocs treats them that way: encrypted, access-controlled, fully audited, and — when you need it — running on infrastructure you control.

🔒
Encrypted end to end

Every connection is served over TLS. Data and uploaded files are encrypted at rest by managed Postgres and object storage.

👤
Role-based access

Reviewer, issuer and consultant each see only what their role allows. Routing is scoped, not open by default.

Complete audit trail

Every action is logged with who and when, and can't be quietly edited away. Tamper-evident by design.

🏢
Private file storage

Drawings and attachments live in a private storage bucket — never a public URL — reached only through signed, time-limited links.

Backed up & recoverable

The database runs on managed Postgres with automated backups, so your register survives hardware faults and mistakes alike.

🔑
You hold the keys

On Enterprise, run on dedicated infrastructure with a self-hosted AI assistant so sensitive specs never leave your control.

Data protection

All traffic between your browser and Brixdocs is encrypted in transit with TLS. Project data is held in managed Supabase Postgres, and uploaded files in a private Supabase Storage bucket — both encrypted at rest. Files are never served from a public path; downloads go through short-lived signed links tied to your session.

Access & identity

Access is governed by project membership and role. A consultant can review and decide the forms routed to them, but never wander the rest of your register. Permissions follow the same lifecycle the documents do, so “who can do what” is always explicit.

  • Role-aware routing — reviewer, issuer and consultant
  • Per-project membership, not blanket organisation access
  • Session-scoped, expiring links for every file download
  • SSO and custom roles available on Enterprise

Accountability & the audit trail

Every state change — raised, reviewed, issued, decided, voided — is recorded with the actor and timestamp. The generated PDF always reflects the form's true status rather than the latest stray action, so the record you hand over in a dispute can't quietly contradict itself.

Hosting & resilience

Brixdocs runs as managed services on Render with a Supabase Postgres database. The database is backed up automatically, and our architecture keeps startup and recovery steps non-fatal so a single failure never takes the whole service down with it.

Keep sensitive content in-house

Some projects can't send specifications to any third-party AI. Brixdocs' assistant is optional and can be pointed at a self-hosted model on your own infrastructure — an office server behind a private tunnel, or a VM you own — so project content never leaves systems you control. Leave it switched off entirely and the rest of Brixdocs works exactly the same.

Your data is yours

You can export any form as a PDF at any time, and your registers remain readable for the life of the project. We don't sell project data or use it to train models.

Responsible disclosure

Found a vulnerability? We want to hear about it. Email security@brixdocs.com with the details and steps to reproduce, and we'll acknowledge it promptly. Please give us a reasonable window to fix an issue before disclosing it publicly.

QUESTIONS?

Need a security
review?

Tell us about your project's requirements and we'll walk you through how Brixdocs handles your data.

security@brixdocs.com