Our commitment
Security is part of how we build and operate the platform — not an afterthought. We combine administrative, technical, and operational controls to protect customer data, reduce risk, and respond quickly when something needs attention.
No system is perfectly secure. We continuously improve our practices, review vendors, and treat reported issues with urgency.
Infrastructure
Customer workloads run on hardened cloud infrastructure with network isolation, managed identity where applicable, and least-privilege defaults for services that support the platform.
- Hosted in reputable cloud regions with redundancy for core platform services
- Network controls, firewalls, and segmentation between public edges and private services
- Automated backups for critical platform data, with restore procedures we rehearse
- Patch and configuration management for systems we operate
Encryption
Data in transit between clients and Build Me Web is protected with modern TLS. Sensitive data at rest is encrypted using industry-standard algorithms managed through our cloud providers’ key management services where supported.
Where you configure custom domains or certificates, we help you terminate HTTPS correctly so visitors reach your sites over encrypted connections.
Access control
Access to production systems is limited to authorized personnel who need it to build, operate, or support the platform.
- Role-based access and least privilege for internal tools and infrastructure
- Strong authentication for staff accounts that can reach customer environments
- Customer account credentials are hashed; you control who joins your workspace
- Audit logging for sensitive administrative actions on the platform
Application security
We design product features with secure defaults and review changes that affect authentication, authorization, payments, and data exposure.
- Secure development practices, code review, and dependency awareness
- Protections against common web risks such as injection, XSS, and CSRF where the platform applies
- Rate limiting and abuse detection on authentication and public APIs
- Separation between customer tenants so one workspace cannot access another’s data
Monitoring and response
We monitor platform health and security-relevant signals so we can detect anomalies, investigate incidents, and restore service quickly. When a security incident affects your account or data, we notify you as required by law and our agreements, with guidance on next steps.
You can check platform availability on our status page.
Data handling
Customer content belongs to you. We process it to provide the Services under your instructions and our Terms of Service. Payment card data, when collected for your storefronts, is handled through payment providers designed for PCI compliance — we do not store full card numbers on Build Me Web systems when those processors are used.
For how we collect and use personal information about you as a Build Me Web customer, see our Privacy Policy.
Vulnerability disclosure
If you believe you have found a security vulnerability in Build Me Web, please tell us responsibly. Email security@buildmeweb.com with enough detail for us to reproduce the issue. Do not access data that is not yours, degrade service for others, or publicly disclose the issue before we have had a reasonable chance to investigate and remediate.
We appreciate good-faith research and will work with reporters to understand and fix valid issues.
Privacy
Security and privacy work together. For details on what personal information we collect and your choices, read our Privacy Policy.
Contact us
Security questions, disclosures, or enterprise security reviews:
- Email: security@buildmeweb.com
- Web: Contact form
- Privacy: Privacy Policy