🚚 New: Start free for 30 days — go annual and we’ll wrap your truck. See the Loyalty Program →
🛡 Trust & Security

Your business runs on CMDBLD.
We take that seriously.

Your estimates, contracts, financials, and client data are protected by database-enforced isolation, encryption, and least-privilege access — built in from day one.

How we protect your data

Tenant isolation

Every company is a separate tenant. Row-Level Security is enforced at the database on every table, so one company can never read or write another company’s data — the isolation is enforced by the database itself, not just the application.

Encryption in transit & at rest

All traffic is served over TLS 1.2+. Data is encrypted at rest by our infrastructure providers. Sensitive credentials (payment, banking, and integration tokens) are held in an encrypted secrets vault, never in plain application tables.

Least-privilege access

Role-based permissions govern what each team member can see and do. Administrative and service credentials are scoped to the minimum required, and secret-bearing operations run through tightly-scoped, audited functions.

Backups & recovery

The database is continuously backed up with point-in-time recovery, so your books, jobs, and documents can be restored after accidental loss.

Secure payments & banking

Card payments are processed by Stripe and bank connections by Plaid — CMDBLD never stores raw card numbers or bank credentials. Vendor banking details are stored encrypted and access-controlled.

Reliable, modern infrastructure

CMDBLD runs on managed, SOC 2-certified cloud infrastructure (our hosting and database providers) with monitoring and automated deploys, so security patches ship quickly.

Compliance status

We believe in being transparent about where we are on the compliance journey rather than overstating it.

Planned
SOC 2 (Type I → II)

SOC 2-aligned controls operate today; a formal audit is on our roadmap.

In place
TLS everywhere

All data encrypted in transit and at rest.

In place
Tenant isolation (RLS)

Database-enforced separation per company.

Security FAQ

Is CMDBLD SOC 2 certified?

Not yet. Our infrastructure providers (hosting and database) are already SOC 2 Type II certified, and we operate SOC 2-aligned controls today — database-enforced tenant isolation, encryption in transit and at rest, least-privilege access, and monitoring. A formal SOC 2 audit for CMDBLD itself is on our near-term roadmap. Contact us for our current security posture and questionnaire responses.

Who can see my data?

Only the members you invite to your workspace, at the permission level you grant them. CMDBLD staff do not access your data except when you request support and grant access, or as strictly required to operate the service.

Do you sell or share my data?

No. We never sell your data. Anonymized, aggregated benchmarks (used to power cost benchmarking) are stripped of anything that could identify your company or clients.

Can I export or delete my data?

Yes. You own your data and can export it, and you can request deletion of your workspace and its data at any time.

How do I report a security issue?

Email security@cmdbld.com. We take reports seriously and will respond promptly.

Questions about security or compliance?

Our team is happy to walk through our controls, share our roadmap, or complete your vendor security review.

Contact security@cmdbld.com

See also our Privacy Policy and Terms of Service.