Annual third-party audit of security, availability, processing integrity, confidentiality, and privacy controls.
Eight compliance frameworks
The acronyms your auditor and lawyer actually care about.
Compliance isn’t a checkbox we tick at the end. It is how the product is shaped from the schema up. Every framework below applies today, in every customer environment, without an enterprise upcharge.
Information Security Management System with documented controls across 14 domains.
Privacy Information Management extension — controls for personal data handling and DSAR workflows.
Cloud-specific security controls covering segregation, virtual environments, and customer responsibilities.
Quality Management System covering change control, incident management, and continuous improvement.
Personal Information Protection and Electronic Documents Act — Canada’s federal privacy law.
European Union General Data Protection Regulation — applied platform-wide, not retrofitted.
Health Insurance Portability and Accountability Act controls for sensitive resident health data.
Six pillars
How we treat your building’s data.
Responsible disclosure
Found a vulnerability? Tell us.
We run a responsible disclosure program for security researchers. Email security@buildingautopilot.ca with a clear repro and we will respond within 24 hours, work with you on scope, and credit you in our hall of fame once the fix ships. We do not pursue good-faith security researchers.