Security at Groundbook AI

Last updated: 2026-08-27

Groundbook AI processes construction drawings, specifications, calculations, and other project information. We use administrative, technical, and organizational safeguards designed to protect that information while operating the Service.

1. Cloud infrastructure and encryption

  • Our primary production application and customer data storage are hosted in the United States on Amazon Web Services (AWS).
  • Customer files, the production database, and database backups are encrypted at rest.
  • Data transmitted to and from the Service is encrypted using TLS.
  • Customer file storage and the production database are private and are not directly accessible from the public internet.

2. Identity and access controls

  • Groundbook AI verifies user identity and authentication before granting access to the application.
  • Project data is available only to the project owner and users granted access through the applicable organization or project. Other customers cannot access your projects.
  • Our production services use scoped AWS roles to limit access to the resources each service needs. Production secrets are stored in AWS Secrets Manager.
  • Single sign-on (SSO) and multi-factor authentication (MFA) are available upon request. Contact support@groundbook.ai to discuss your organization's requirements.

3. Customer data and AI providers

  • Commercial AI model providers used to process requests operate under terms that prohibit them from training their models on Customer Project Data.
  • Service providers may process information only to provide services to Groundbook and must protect it under their applicable contractual obligations.
  • We do not sell personal information or Customer Project Data, and we do not directly provide or show Customer Project Data to another customer.

For details about Groundbook's internal model-training process, available choices, and data handling practices, see our Privacy Policy.

4. Application and deployment security

  • File uploads use time-limited URLs, and uploaded documents are validated before processing.
  • Our web application uses security headers that enforce HTTPS and help protect against framing, content-type confusion, and unnecessary browser permissions.
  • Web changes pass automated tests, linting, and a production build before deployment.
  • Production deployments use short-lived credentials, and production container images are deployed by immutable digest.

5. Backups and deletion

Encrypted automated database backups and versioned object storage support recovery from user or system error. Deleting a project in the app removes it from the active workspace but is not a permanent-deletion request.

To request permanent deletion of Customer Project Data, email support@groundbook.ai. For additional information about retention and deletion, see our Privacy Policy.

6. Report a security concern

If you believe you have found a security issue involving Groundbook AI, email support@groundbook.ai with a description, steps to reproduce, and any affected URLs. Please do not include Customer Project Data or other sensitive information unless it is necessary to explain the issue.

For other security questions or to discuss your organization's requirements, contact support@groundbook.ai.