Scoped access
Applications are designed around least-privilege access, explicit user and service identities, customer-controlled authorization, and the minimum Procore permissions required for the workflow.
Security principles
Every customer system has different data, permissions, hosting, and risk. We define the security model during solution design and document the controls that apply to that engagement.
Ask a security questionApplications are designed around least-privilege access, explicit user and service identities, customer-controlled authorization, and the minimum Procore permissions required for the workflow.
We minimize stored data, protect data in transit, use managed infrastructure controls where appropriate, and define retention and deletion requirements with the customer.
Production designs include appropriate logging, error reporting, traceability, and exception handling so failures can be investigated without exposing unnecessary sensitive data.
Security questionnaires, architecture reviews, incident terms, recovery requirements, vendor documentation, and testing expectations are handled within the scope of the customer engagement.