Trust & Security

Your jobsite data is
the most protected
thing we build.

Every photo your crew takes, every blueprint you upload, and every number we hand back is treated like evidence you may one day have to produce. Encrypted the moment it leaves the site, locked down at every layer after that, and never anyone else's to look at. Here is exactly how, control by control, with no hand waving.

A concrete pour photographed on an active jobsite, captured in Quoto Build TLS 1.2+ in transit
AES-256 at rest
  • AES-256 encryption on every file at rest
  • TLS 1.2+ encryption on every byte in transit
  • 4 layers of defense around your project data
  • Zero of your data sold, rented, or brokered
Defense In Depth

Four layers between the internet and your site

There is no single wall to get through, because a single wall is a single point of failure. Your project data sits at the centre, and nothing reaches it without crossing every layer above it.

Monitoring and response

Infrastructure is watched continuously, with a defined path for investigating and containing anything unusual.

Access control

Every account, service, and engineer gets the minimum access required, and nothing beyond it.

Encryption in transit

TLS 1.2 or higher on every connection, from the phone in a hand on site to the browser on a desk.

Encryption at rest

AES-256 on every photo, video, blueprint, model, and report the moment it lands in storage.

Your project data
Our Principles

Six commitments, and what each one actually means

Security language is cheap. So every principle below is written with the mechanism attached, in the words we would use with your IT team.

Encrypted by default, with no exceptions

There is no setting to turn encryption off, no unencrypted tier, and no plan where your footage is treated as less sensitive. Every file is encrypted at rest with AES-256 and every connection is protected with TLS 1.2 or higher. The strongest posture we offer is the only posture we offer.

Least privilege, all the way down

Access is granted by exception, not by default. Accounts, internal services, and our own engineers each hold the narrowest permissions that let them do the job, so a single credential is never a key to everything. Permissions are reviewed as teams and projects change.

Your projects are isolated from everyone else’s

Every account works inside its own logical boundary. One company’s site footage, takeoffs, cost structures, and reports are never visible from another company’s workspace, and requests are authorized against your account on the way in, not filtered on the way out.

Privacy designed in, not bolted on

We collect what the platform needs to do its work and no more. Your crews appear in your footage because you captured them, so that footage stays inside your account, governed by the same privacy principles the modern data protection regulations are founded on. Nothing about your projects is sold, rented, or brokered. Ever.

Built to survive a bad day

Your project history is the record you would be asked to produce in a dispute, so it is treated that way. Data is backed up redundantly across isolated infrastructure, restores are exercised rather than assumed, and a hardware failure on our side is not an event you should ever have to hear about.

Transparency, all the way down

Most vendors hand your IT team a summary and hope the questions stop there. We would rather name the actual controls, walk your reviewers through the architecture behind each one, and let them interrogate all of it. Ask us anything about how Quoto Build handles your data and you will get a straight answer, in writing.

Follow The Data

One photo, end to end

The clearest way to judge a platform's security is to trace a single file through it. So here is one, from the moment a phone comes out of a pocket to the moment a report reaches a client.

  1. A superintendent capturing a scaffolded structure on a tablet
    01

    Captured on site

    A photo, video, 360 capture, blueprint, or drone flight leaves the device over a connection secured with TLS 1.2 or higher. It is encrypted before it ever reaches us.

  2. The same capture, unreadable once it is encrypted at rest
    02

    Stored under AES-256

    The file lands in enterprise cloud storage inside your account’s own boundary, encrypted at rest with AES-256, and replicated to redundant backups.

  3. Quoto Build boxing a hazard on a jobsite frame and naming it
    03

    Analyzed for you alone

    Quoto Build reads the frame for measurements, materials, progress, and hazards. The analysis runs against your data to produce your result, and stays inside your account.

  4. 04

    Shared on your terms

    Reports, takeoffs, and estimates go to the people you name, over encrypted connections, with access you can grant and revoke.

Data Ownership

It is your site. It stays your data.

Your footage, your measurements, your cost structures, and your reports belong to your company, not to us. We hold them so the platform can do its job for you, and that is the whole extent of it.

  • Yours to export, at any time
  • Yours to delete, on request
  • Never sold, rented, or brokered
  • Never visible from another company's account
Straight Answers

The questions
IT teams ask us.

Something not covered? Ask us directly →

Is my project data encrypted?

Always, and in both states that matter. Everything you upload is encrypted in transit using TLS 1.2 or higher, and encrypted at rest using AES-256. That applies to site photos, video, 360 captures, drone footage, blueprints, 3D models, takeoffs, cost structures, and every report generated from them. There is no tier of Quoto Build where this is optional.

Who at Quotograph can see my footage?

As close to nobody as running a platform allows. Access is granted by exception and scoped to the narrowest job it is needed for, which in practice means engineers work against systems rather than browsing your projects. Your site footage is not a resource we treat as ours to look through.

How does Quoto Build line up with the security frameworks in our questionnaire?

Quoto Build is built to the principles those frameworks are founded on: security, availability, processing integrity, confidentiality, and privacy. Every control family on this page maps to one of them, from AES-256 at rest and TLS 1.2 or higher in transit, through least privilege access and account isolation, to monitoring, incident response, and tested restores. Send us your questionnaire and we will work through it line by line with your security team, and take them into the architecture behind each answer.

Where is my data stored?

On enterprise cloud infrastructure, encrypted at rest, with redundant backups held on isolated infrastructure so a single failure cannot take your project history with it. If your organization has specific residency or hosting requirements, talk to us before you roll out and we will work through them with you.

Do you sell or share my project data?

No. Your projects are not a product we sell. We do not sell, rent, or broker your data, your footage, your measurements, or your pricing to anyone, and we do not expose one customer’s work inside another customer’s account.

What happens to my data if we stop using Quoto Build?

It remains yours. You can export your projects, and you can ask us to delete your data, which we will action rather than negotiate. Nothing about leaving is designed to hold your project history hostage.

Can my IT team review this before we roll out?

Please do, and bring the hard questions. Email info@quotograph.io and we will take your security team through the architecture, the controls listed on this page, and anything in your questionnaire. We would rather spend an hour with your reviewers up front than have you guessing.

Put us in front of
your toughest reviewer

We would rather earn a rollout by answering hard questions than win one by avoiding them.