Logo
Navigation
Home Solutions Pricing About Contact Book a Demo
My Account
Log In

Install our app on your home screen for quick and smooth access.

My Cart
Total $0.00
Trust & security

Security your owners, lenders and auditors can verify

D50 OS holds contracts, drawings, payroll hours and financial records. We treat that data the way a bank treats a ledger.

  • Encrypted in transit and at rest
  • Immutable audit trail
  • Role and record level access
  • Daily backups
Security

Controls that are in place today

Not a roadmap. These are the safeguards running on every account right now.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest, including documents and photos.

Least privilege

Role, company and record level permissions, reviewed at every release.

Immutable audit trail

Every create, edit, approval and deletion is versioned with actor and timestamp.

Strong authentication

Two-factor authentication for every account, SSO and SCIM on Enterprise.

Backups and recovery

Encrypted daily backups with point-in-time restore and a tested recovery plan.

Continuous monitoring

Intrusion detection, anomaly alerts and 24/7 infrastructure monitoring.

Secure development

Peer-reviewed code, dependency scanning and annual third-party penetration testing.

Documented policies

Access control, incident response, vendor risk and business continuity policies available on request.

Data residency you choose

Enterprise customers select the hosting region for their tenant, and data does not leave it.

We do not sell or train on your data

Your project records are never sold, shared with third parties or used to train models outside your own account.

Exit without hostage-taking

Full export of every record, document and photo on request, and again 90 days after termination.

How we handle an incident

A documented response plan, rehearsed twice a year.

0 - 15 min

Detect and triage

Automated alerting pages the on-call engineer, who classifies severity and opens an incident channel.

Within 1 hour

Contain

Affected services are isolated, credentials rotated and the blast radius bounded.

Within 24 hours

Notify

Affected customers receive a factual notice with scope, impact and interim guidance.

Within 5 days

Post-mortem

A written root cause analysis with corrective actions and dates is delivered to affected customers.

Security questions we get asked

In hardened data centres with SOC 2 certified infrastructure providers. Enterprise customers choose their region and it is documented in the contract.

Yes. We provide a completed security questionnaire, our policy set and the summary from the most recent penetration test under NDA. Customer-run testing can be scheduled.

Administrators deactivate the account immediately and all sessions are terminated. On Enterprise, SCIM provisioning removes access automatically from your identity provider.

99.9% monthly availability on Build and Enterprise, with service credits defined in the agreement and a public status page.

No. External collaborators only see the specific records shared with their company. Pricing, other trades' documents and internal notes are never exposed.

Need our security package for review?

Send us your questionnaire. We return a completed response, our policy set and the latest penetration test summary under NDA.