Security & Trust

Built so your contracts stay yours.

In construction, your numbers are your edge. RCS is engineered so the contracts, quotes, and pricing you review stay private to your team — encrypted, access-controlled, and never used to train AI. Here is exactly how.

Security questions or a vendor review? security@redlineconstructionsolutions.com

Your private cloud

Production workspaces deploy into your own cloud account. Contracts, quotes, and pricing live on infrastructure you own — not on a shared platform.

Encrypted end to end

TLS 1.2+ in transit and AES-256 at rest. Credentials are handled with industry-standard protocols and never stored in plaintext.

Never trains AI

Your contract data is used to produce your review only — never to train, fine-tune, or benchmark any AI model, ours or a third party's.

You hold the keys

Role-based access scoped to your team, audited sign-ins, and data you can delete on your own schedule. You decide who sees what, and for how long.

The detail

Our security posture, in plain terms.

Honest status on each control — what's in place today, and what's on the way.

Deployment & residency

Runs inside infrastructure you control

In place
  • Production workspaces are deployed into your own private cloud account, so your data never co-mingles with another firm's on shared, multi-tenant AI software.
  • Free pilots run on RCS's secure hosted instance; pilot data is isolated per workspace and can be deleted at the end of the pilot.
  • Data-residency requirements (US / EU / gov) are accommodated at deployment for production customers.
Encryption

Protected in transit and at rest

In place
  • All traffic is served over HTTPS with TLS 1.2 or higher.
  • Stored contract data is encrypted at rest with AES-256 via the underlying cloud provider.
  • Session tokens are cryptographically signed (HMAC); secrets and API keys are held in the platform's encrypted environment store, never in source or in plaintext.
AI & data use

Your contracts are used for your review — and nothing else

In place
  • Contract data is sent to the AI model for inference only — to produce your redline. It is NEVER used to train, fine-tune, evaluate, or benchmark any machine-learning model or large language model.
  • Our AI sub-processors (Anthropic's Claude API and AWS Bedrock) do not train their models on data submitted through their APIs.
  • This commitment is contractual, not just aspirational — it is written into how the product is built and into the agreements we sign. It directly satisfies the data-use rules of partner marketplaces such as Procore.
Access & authentication

Least-privilege by default

In place
  • Role-based access control: reviewers and approvers see only what their role permits, scoped to their own workspace.
  • Sign-ins are authenticated and audited; final approvals are recorded with the approver's name and a timestamp.
  • Single sign-on (Microsoft / Google) is available for production workspaces during onboarding.
Retention & deletion

You decide what's kept, and for how long

In place
  • Contract data is retained only as long as needed to deliver and store your reviews, per your configured retention policy.
  • You can delete a contract, a review, or your entire workspace on your own schedule.
  • We do not sell, rent, or redistribute your data to anyone, under any circumstance.
Privacy & compliance

Built to the standards your customers expect

In progress
  • Privacy practices are aligned with GDPR and CCPA principles; see our Privacy Policy for how data is handled.
  • SOC 2 Type II: readiness program underway. We are happy to share current status and our roadmap under NDA.
  • Independent penetration testing and a formal vulnerability-disclosure program: planned as part of our marketplace-readiness track.
Sub-processors

The vendors in our supply chain.

We keep this short on purpose. Every sub-processor is named, and none of them train AI on your data.

VercelApplication hosting / edge delivery
SupabaseEncrypted data storage (Postgres)
Anthropic (Claude API)AI inference — no training on inputs
AWS BedrockOptional private AI inference — no training on inputs
ResendTransactional email (notifications)

Found a vulnerability? Tell us.

We welcome responsible disclosure. Email us with the details and steps to reproduce, and we'll acknowledge within two business days and keep you posted through the fix. Please don't access another customer's data while testing.

security@redlineconstructionsolutions.com

RCS is an independent product and is a drafting aid, not a law firm. See our Privacy Policy and Terms.

Redline Construction Solutions

Redline construction contracts in minutes — not weeks. Reviewed against current law and your standards, in your own private cloud.