Enterprise-grade security. Hosted on AWS. Protection for your project data you can rely on.
TLS 1.3 in transit, AES-256 at rest on our cloud infrastructure. Connected accounting credentials get an extra layer of encryption at the application level.
All data stored in AWS data centres in Sydney, Australia. Fully compliant with local data protection laws.
2FA via SMS or authenticator app for an extra layer of account protection.
Role-based access so users only see what they need to.
Full audit trail — who accessed what, when, and from where.
Quarterly penetration testing and assessments by independent third parties.
Information security management certification
Security and availability controls
Data handled in line with applicable privacy law, including the Privacy Act 2020 (NZ) for New Zealand customers
All data stored in AWS Sydney region, ensuring:
Our incident response plan ensures rapid detection, containment, and resolution.
24/7 monitoring with immediate alerts
Affected systems isolated within 1 hour
Users notified within 72 hours
Fix, strengthen defences, post-mortem
Found a vulnerability? Report it responsibly and we commit to:
Email security@buildpaperless.ai with details. We respond within 24 hours.
We assess and reproduce the issue within 48 hours.
Critical issues patched within 7 days, others based on severity.
Coordinated disclosure after fix. Recognition for responsible reporting.