Last updated: 16 August 2026
Security
This page describes how BuildTrack protects Customer Data and personal data. It is information, not a numbered service-level agreement and not a claim of ISO, SOC 2 or other certification we have not obtained.
Related documents: Privacy Policy, Data Processing Addendum, subprocessors.
1. Tenant isolation
Product data is scoped to your organisation. Application queries use your company identifier from the authenticated session. We design authorisation so one workspace cannot read another workspace’s records.
2. Authentication and access
Users sign in with unique credentials or Google sign-in. Access within a workspace is role-based. Staff of BuildTrack may access a workspace only as needed to operate, secure or support the Service (for example when you open a support request). Optional biometric unlock on the mobile app stays on the device.
3. Encryption and files
Traffic to the Service is encrypted in transit (TLS). Uploaded files and generated documents are stored in private object storage (Amazon S3, Singapore region by default) and retrieved with time-limited signed URLs rather than public buckets.
4. Payments and webhooks
Subscription card details are handled by Stripe. Optional job-invoice collections use CHIP when you connect it. Incoming payment and email webhooks are verified with provider signatures before we apply them.
5. Application security practice
We maintain automated checks in our development pipeline, including API contract guards, SQL composition checks, dependency review, static analysis, secret scanning, and periodic dynamic scans of preview deployments. These reduce risk; they are not a guarantee that defects will never occur.
6. Monitoring
The mobile app may send crash and diagnostic events to Sentry so we can fix defects. That monitoring is not used to reconstruct your commercial records. Advertising pixels (Google Ads, Meta) are not loaded in the signed-in product.
7. Your responsibilities
Use unique accounts, keep credentials confidential, choose appropriate roles, review who you invite, and disconnect integrations you no longer need. You decide which Customer Data you store, including GPS, photos and WhatsApp.
8. Reporting a vulnerability
If you discover a security issue, email hello@buildtrack.com.my. Include a description, potential impact, Do not access or exfiltrate other customers' data. We aim to acknowledge good-faith reports within two business days.


