Security principles

Security designed around the exact workflow.

Every customer system has different data, permissions, hosting, and risk. We define the security model during solution design and document the controls that apply to that engagement.

Ask a security question

Scoped access

Applications are designed around least-privilege access, explicit user and service identities, customer-controlled authorization, and the minimum Procore permissions required for the workflow.

Data handling

We minimize stored data, protect data in transit, use managed infrastructure controls where appropriate, and define retention and deletion requirements with the customer.

Operational visibility

Production designs include appropriate logging, error reporting, traceability, and exception handling so failures can be investigated without exposing unnecessary sensitive data.

Customer-specific review

Security questionnaires, architecture reviews, incident terms, recovery requirements, vendor documentation, and testing expectations are handled within the scope of the customer engagement.