BuildersAlpha is built for the security and compliance requirements of the world's most demanding engineering and finance organizations. This page summarizes how we protect your data and keep the platform available.
Independently audited security controls
AES-256 at rest, TLS 1.2+ in transit
Each assessment runs in its own container
Enterprise identity and least-privilege access
Data rights and regional handling honored
Complete, exportable activity records
Regular third-party security testing
Monitored availability across the platform
BuildersAlpha provides an AI-native assessment platform used by hiring teams to evaluate how candidates build with AI. Security and privacy are designed into the platform rather than added afterward. We maintain a formal information security program, audited controls, encryption everywhere, isolated assessment environments, and a documented continuity and incident-response process. To request our SOC 2 report, penetration-test summary, or a completed security questionnaire, contact our team.
Our controls are independently audited and mapped to widely recognized frameworks. Available documentation includes:
Reports and our DPA are available under NDA on request.
The platform runs on enterprise cloud infrastructure (primary region in the United States) with managed, redundant components. Production is isolated within a dedicated virtual network, segmented from corporate systems, and protected by a web application firewall and DDoS mitigation at the edge.
| Layer | How it's protected |
|---|---|
| Application & API | Autoscaling compute behind a managed load balancer with WAF |
| Assessment sandboxes | Ephemeral, isolated containers provisioned per session and destroyed after |
| Databases | Managed, high-availability data stores with automated failover |
| Edge & DNS | Global CDN with DDoS protection and TLS termination |
| Monitoring | End-to-end observability, alerting, and centralized logging |
All data is encrypted in transit using TLS 1.2 or higher on every client-facing endpoint, and at rest using AES-256 managed encryption across all data stores and backups. Secrets and keys are stored in a managed key-management service with restricted access.
Customer access supports SSO via SAML 2.0 and SCIM provisioning, with role-based access control mapping admins, hiring managers, and reviewers to least-privilege permissions. Internally, employee access to production follows least privilege, requires multi-factor authentication, and is logged and reviewed. Access is granted on a need-to-know basis and revoked promptly when no longer required.
Each assessment runs in its own isolated, ephemeral environment with no access to your internal systems or to other candidates' sessions. We apply identity verification and anti-cheat measures to keep scores trustworthy. Candidate work product, prompts, and session activity are processed to produce the intelligence report and are retained and deleted according to customer configuration and our Data Processing Agreement.
We target 99.9% monthly availability across production endpoints, with recovery objectives defined by incident severity. Specific commitments and service credits are set out in your enterprise agreement and SLA.
| Scenario | Recovery Time (RTO) | Recovery Point (RPO) |
|---|---|---|
| Full outage | < 1 hour | < 1 hour |
| Partial degradation | < 4 hours | < 4 hours |
| Non-critical issue | < 1 business day | < 24 hours |
We classify incidents by severity and follow a documented response process with defined acknowledgement and update cadences. Affected customers are notified through email and our status page, and a post-incident report is shared for major incidents.
| Severity | Definition | Acknowledge | Update cadence |
|---|---|---|---|
| P1 — Critical | Platform-wide outage or data-integrity risk | 15 min | Every 30 min |
| P2 — High | Significant degradation or single-component failure | 30 min | Hourly |
| P3 — Medium | Limited impact with a workaround available | 4 business hrs | Daily |
Critical components are redundant and fail over automatically. We maintain a documented disaster-recovery plan covering data-store recovery, compute replacement, and regional failure, and we test recovery procedures on a regular schedule. Recovery objectives are defined per scenario as shown above.
| Data | Method | Retention |
|---|---|---|
| Customer & assessment data | Automated point-in-time backups | Configurable; default 30 days |
| Candidate work product | Encrypted storage | Per customer configuration & DPA |
| Application configuration | Version controlled | Indefinite |
| Logs | Centralized aggregation | Defined retention window |
All backups are encrypted at rest. Customers can request deletion of candidate data in accordance with their agreement.
We patch systems on a regular cadence, scan for vulnerabilities, and engage independent third parties for periodic penetration testing. Findings are tracked to remediation. We run a responsible-disclosure process; report any suspected vulnerability to info@buildersalpha.com.
For our SOC 2 report, penetration-test summary, DPA, subprocessor list, or a completed security questionnaire, contact info@buildersalpha.com or reach out through our contact form. See also our Subprocessors and Privacy Policy pages.
We'll share our SOC 2 report, DPA, and answer your security questionnaire under NDA.