Trust & security

Your books and your customers' data, protected.

Construction Scope is built on industry-standard security practices. Customer payment data never touches our servers — it's tokenized and held by Stripe.

SOC 2
Type II audited
PCI DSS
Stripe-managed payments
AES-256
At rest & in transit
99.95%
Uptime SLA
Standard on every plan

Encryption everywhere

All data is encrypted in transit with TLS 1.3 and at rest with AES-256. Backups are encrypted and stored across multiple regions.

Standard on every plan

Role-based access

Owner, Admin, Office, Crew, and Read-only roles. Crews can log time and materials but cannot view financial reports.

Standard on every plan

Stripe-managed payments

Card and ACH details are tokenized and held by Stripe — they never touch Construction Scope servers. PCI compliance is inherited.

Standard on every plan

Two-factor auth

Required for Owners and Admins. SMS and authenticator app supported. SSO available on the Pro plan.

Standard on every plan

Audit log

Every estimate sent, change order approved, and invoice paid is logged with user, IP address, and timestamp.

Standard on every plan

Backed up nightly

Automatic backups every six hours. 30-day point-in-time restore for paid plans, 90-day for Pro.

Standard on every plan

GDPR & CCPA

Data export and deletion available on request. Customer-facing privacy notices included in approval emails.

Standard on every plan

Bug bounty

Active disclosure program with payouts up to $10,000. Report findings to security@constructionscope.net.

Standard on every plan

Sub-processors disclosed

Stripe, AWS, Postmark, and Sentry. Full list at constructionscope.net/sub-processors.