Eight compliance frameworks · Zero shortcuts · Built audit-ready

Property data treated like bank data.

Resident contact info. Visitor logs. Incident reports. Insurance certificates. Board minutes. BuildingAutopilot is built to handle the most sensitive operational data in your building with the same rigor financial services treat your bank account — encrypted, audited, compliant.

256-bit
AES encryption
At rest, in flight, in backups
99.99%
Uptime SLA
52 min annual budget
< 24h
DSAR fulfillment
Access, transfer, deletion
0
Reportable breaches
Since day one

Eight compliance frameworks

The acronyms your auditor and lawyer actually care about.

Compliance isn’t a checkbox we tick at the end. It is how the product is shaped from the schema up. Every framework below applies today, in every customer environment, without an enterprise upcharge.

SOC 2Type II

Annual third-party audit of security, availability, processing integrity, confidentiality, and privacy controls.

ISO 27001ISMS

Information Security Management System with documented controls across 14 domains.

ISO 27701PIMS

Privacy Information Management extension — controls for personal data handling and DSAR workflows.

ISO 27017Cloud

Cloud-specific security controls covering segregation, virtual environments, and customer responsibilities.

ISO 9001QMS

Quality Management System covering change control, incident management, and continuous improvement.

PIPEDACanada

Personal Information Protection and Electronic Documents Act — Canada’s federal privacy law.

GDPREU

European Union General Data Protection Regulation — applied platform-wide, not retrofitted.

HIPAAUS Health

Health Insurance Portability and Accountability Act controls for sensitive resident health data.

Six pillars

How we treat your building’s data.

Encryption

Encrypted at rest. Encrypted in flight. Encrypted in backups.

AES-256 at rest for every database column. TLS 1.3 in flight across every API. Customer-managed keys available on the enterprise tier. Nothing leaves our infrastructure unencrypted.

  • AES-256 column-level encryption at rest
  • TLS 1.3 enforced on every API endpoint
  • Customer-managed KMS keys (enterprise tier)
  • Encrypted, geo-redundant continuous backups

Access control

Role-aware permissions, mandatory MFA, zero-trust by default.

Every API call, every screen, every record check is scoped by role and tenant. OAuth 2.0 / OIDC for staff. Optional SSO. Mandatory MFA for admin accounts. Time-boxed elevated sessions for sensitive ops.

  • Role-based access control across 12+ personas
  • OAuth 2.0 / OpenID Connect for staff sign-in
  • Optional SAML / SCIM for enterprise SSO
  • Mandatory MFA for admin, board, and finance roles

Audit & monitoring

Immutable audit log. Every action, every operator.

Every administrative action is logged with operator, timestamp, IP, request ID, and before/after diff. The audit log is append-only — even we can’t rotate it. The auditor walks in and reads exactly what happened.

  • Append-only audit log across all admin operations
  • Operator, IP, timestamp, request ID on every event
  • Real-time anomaly detection on privileged actions
  • 24/7 monitoring with on-call rotation

Privacy by design

DSAR in hours, not weeks. Data minimization, not vacuuming.

Data subject access requests fulfilled with one click — export, transfer, or delete. We collect the minimum required for each feature, retain only as long as legally required, and document every processing purpose in our ROPA.

  • One-click DSAR fulfillment (access, rectification, deletion)
  • Data minimization by design — 14 processing categories documented
  • Retention policies enforced automatically at the schema layer
  • Bilingual privacy notices (English / fr-CA)

Resilience

99.99% uptime SLA. Disaster recovery the auditor actually wants.

Geo-redundant continuous backups. Point-in-time recovery to any minute in the last 30 days. Documented runbooks for every failure mode. Quarterly disaster recovery drills with measured RTO/RPO.

  • 99.99% uptime SLA (52 minutes annual downtime budget)
  • Geo-redundant backups across two regions
  • Point-in-time recovery to any minute in last 30 days
  • Quarterly DR drills with documented RTO/RPO

Secure development

SAST every pull request. DAST every release. Pentests every year.

Static analysis runs on every PR. Dynamic application security testing runs on every release. Third-party penetration test annually with findings published to enterprise customers under NDA.

  • SAST scanning on every pull request
  • DAST scanning on every staging release
  • Annual third-party penetration testing
  • Dependency vulnerability scanning continuously

Responsible disclosure

Found a vulnerability? Tell us.

We run a responsible disclosure program for security researchers. Email security@buildingautopilot.ca with a clear repro and we will respond within 24 hours, work with you on scope, and credit you in our hall of fame once the fix ships. We do not pursue good-faith security researchers.

Want the full security questionnaire?

We share our completed CAIQ, SIG, and pentest summary under NDA. Tell us which framework your team needs and we will send it over.

Request the security pack