Security
Last updated: June 2026VU-QC is built for construction teams handling sensitive project documents — contracts, engineering drawings, financial data, and quality records. Security is foundational to our platform, not an afterthought.
🔒 Encryption at Rest
All project documents, analysis results, and user data are encrypted at rest using AES-256 encryption. Database storage uses encrypted volumes with automated key rotation.
🔐 Encryption in Transit
All communications between your browser and VU-QC use TLS 1.2+ encryption. API traffic is encrypted end-to-end. No unencrypted data leaves the platform.
🛡️ Access Control
Role-based access control (RBAC) ensures users only access projects and data they are authorized to view. JWT-based authentication with secure session management.
🏗️ Infrastructure Security
VU-QC is hosted on AWS with VPC isolation, security groups, and network access controls. Infrastructure is managed with infrastructure-as-code for auditability.
📋 Audit Logging
Every significant action — document uploads, analysis runs, data exports, permission changes — is logged in an immutable audit trail for compliance and accountability.
🗄️ Data Isolation
Project data is logically isolated per organization. Documents are stored in dedicated, encrypted S3 buckets with access policies scoped to authorized users.
🔄 Backup & Recovery
Automated daily backups with point-in-time recovery. Database snapshots are encrypted and stored in geographically separate regions. RPO ≤ 15 minutes, RTO ≤ 1 hour.
🤖 AI Data Handling
Uploaded documents are processed by AI models solely to generate your analysis results. We do not use your project data to train AI models. Analysis data is not shared across organizations.
📊 Compliance
Our security practices align with SOC 2 Type II controls, ISO 27001 principles, and construction industry data handling standards. We conduct regular security assessments.
Responsible Disclosure
If you discover a security vulnerability in VU-QC, please report it responsibly by contacting info@vu-qc.com. We take all reports seriously and will respond within 48 hours.
Questions?
For security-related inquiries, contact our team at info@vu-qc.com.