SECURITY & COMPLIANCE

Your event data is in safe hands

BuilderBase is built to protect organizer, sponsor, and participant data at every stage of an event, from application to post-event reporting.

  • TLS encryption
  • EU data residency
  • Role-based access
Standards & controls

What runs under your events.

  • GDPRGDPR aligned*
  • 256-bitAESEncryption at rest*
  • TLS 1.2+Encryption in transit
  • EUIRELANDEU data residency
  • SOC 2TYPE IIInfrastructure providers*
  • ISO27001Infrastructure providers*
  • Per-organization data
  • ROLE-BASEDOrganizer & admin tools*

SOC 2 and ISO 27001 certifications are held by our infrastructure providers, Cloudflare and Supabase. BuilderBase is not yet independently certified.

  • GDPR We build to GDPR principles and operate from the EU. There is no certification to hold against GDPR — this is alignment, not an audit result.
  • 256-bit AES Applied by our infrastructure providers on the storage layer, not implemented by BuilderBase.
  • SOC 2 Type II Held by Cloudflare and Supabase. BuilderBase is not itself SOC 2 certified.
  • ISO 27001 Held by Cloudflare and Supabase. BuilderBase is not itself ISO 27001 certified.
  • Role-based access Roles are coarse today. Granular, tiered permissions are on the roadmap.

Still being built: we do not yet run a formal, structured risk management program, our incident response is not yet documented with defined response timelines, and onboarding, offboarding, and confidentiality processes are still being formalized as the team grows. We are happy to talk through any of it.

Security & encryption

We keep your event data safe.

Isolation by default, least privilege on access, encryption on the wire.

Data protection

Every event on BuilderBase runs in its own isolated space. Applications, submissions, judging scores, and sponsor information are separated by organization, so one event’s data is never exposed to another.

Controlled access & encryption

Access to organizer and admin tools is role-based. API access is scoped to specific routes rather than broad account-level permissions, so a compromised key cannot reach more than it needs to. Data is encrypted in transit, and our infrastructure providers encrypt data at rest.

Privacy & compliance

We keep your event data private.

Where your data lives, who can reach it, and what we will never do with it.

  1. 01

    GDPR aligned

    BuilderBase is built and operated from Stockholm with GDPR principles at the center of how we handle personal data.

  2. 02

    No AI training on your data

    We do not use event, applicant, or submission data to train foundation AI models, and we do not share it with external vendors for that purpose.

  3. 03

    Regional hosting

    Your data is stored in EU-based data centers in Ireland, supporting EU data residency requirements.

  4. 04

    Independently certified infrastructure

    BuilderBase itself is not yet SOC 2 or ISO 27001 certified. Our underlying infrastructure providers, Cloudflare and Supabase, are independently certified to SOC 2 and ISO 27001, and we build on top of that foundation.

Enterprise security review? We will complete your questionnaire and walk your team through our current controls. Email us.

Trusted by
DellNVIDIAReplit

Security questions, answered plainly.

Including the parts we are still building.

How do you uphold information security?
We combine infrastructure-level controls with BuilderBase-specific safeguards: encrypted connections, scoped API access, and per-organization data isolation. Our infrastructure providers, Cloudflare and Supabase, are independently certified to SOC 2 and ISO 27001. We are an early-stage company still working toward our own formal certification, and we are glad to walk enterprise teams through our current controls in detail.
How do you control access to your systems?
Access to organizer and admin tools is role-based. We are building toward more granular, tiered permissions as the platform grows. Internal access to production systems is limited to team members who need it for their role.
How do you manage risk?
We monitor our systems continuously and respond to issues as they come up. We do not yet run a formal, structured risk management program. That is on our roadmap as we take on larger enterprise engagements.
How do you secure operations?
Our infrastructure runs on Cloudflare Workers, which execute in isolated, sandboxed environments, with Supabase for data storage in Ireland. We validate inputs strictly and monitor errors and performance continuously.
How do you uphold security with your team?
Our team is small, and access to customer data is limited to those who need it for their role. We are formalizing onboarding, offboarding, and confidentiality processes as the team grows.
Do you use our data to train AI models?
No. BuilderBase does not use your event data to train foundation AI models or share it with external vendors for that purpose.
What happens if there is a security incident?
Today our team is small and directly reachable, so we respond quickly. We are formalizing this into a documented incident response process with defined timelines as we scale.

Need a deeper review?

We will sit down with your security team, answer the questionnaire, and be straight about what is in place today and what is on the roadmap.