Trust Center

Security, privacy, and compliance.

BuildersAlpha is built for the security and compliance requirements of the world's most demanding engineering and finance organizations. This page summarizes how we protect your data and keep the platform available.

🛡️

SOC 2 Type II

Independently audited security controls

🔐

Encryption

AES-256 at rest, TLS 1.2+ in transit

🧱

Isolated sandboxes

Each assessment runs in its own container

🔑

SSO & RBAC

Enterprise identity and least-privilege access

🌍

GDPR & CCPA

Data rights and regional handling honored

👁️

Audit logging

Complete, exportable activity records

🧪

Penetration tested

Regular third-party security testing

99.9% uptime

Monitored availability across the platform

On this page

Overview

BuildersAlpha provides an AI-native assessment platform used by hiring teams to evaluate how candidates build with AI. Security and privacy are designed into the platform rather than added afterward. We maintain a formal information security program, audited controls, encryption everywhere, isolated assessment environments, and a documented continuity and incident-response process. To request our SOC 2 report, penetration-test summary, or a completed security questionnaire, contact our team.

Certifications & compliance

Our controls are independently audited and mapped to widely recognized frameworks. Available documentation includes:

Reports and our DPA are available under NDA on request.

Infrastructure & hosting

The platform runs on enterprise cloud infrastructure (primary region in the United States) with managed, redundant components. Production is isolated within a dedicated virtual network, segmented from corporate systems, and protected by a web application firewall and DDoS mitigation at the edge.

LayerHow it's protected
Application & APIAutoscaling compute behind a managed load balancer with WAF
Assessment sandboxesEphemeral, isolated containers provisioned per session and destroyed after
DatabasesManaged, high-availability data stores with automated failover
Edge & DNSGlobal CDN with DDoS protection and TLS termination
MonitoringEnd-to-end observability, alerting, and centralized logging

Data encryption

All data is encrypted in transit using TLS 1.2 or higher on every client-facing endpoint, and at rest using AES-256 managed encryption across all data stores and backups. Secrets and keys are stored in a managed key-management service with restricted access.

Access control & authentication

Customer access supports SSO via SAML 2.0 and SCIM provisioning, with role-based access control mapping admins, hiring managers, and reviewers to least-privilege permissions. Internally, employee access to production follows least privilege, requires multi-factor authentication, and is logged and reviewed. Access is granted on a need-to-know basis and revoked promptly when no longer required.

Assessment integrity & candidate data

Each assessment runs in its own isolated, ephemeral environment with no access to your internal systems or to other candidates' sessions. We apply identity verification and anti-cheat measures to keep scores trustworthy. Candidate work product, prompts, and session activity are processed to produce the intelligence report and are retained and deleted according to customer configuration and our Data Processing Agreement.

Availability commitment

We target 99.9% monthly availability across production endpoints, with recovery objectives defined by incident severity. Specific commitments and service credits are set out in your enterprise agreement and SLA.

ScenarioRecovery Time (RTO)Recovery Point (RPO)
Full outage< 1 hour< 1 hour
Partial degradation< 4 hours< 4 hours
Non-critical issue< 1 business day< 24 hours

Incident response

We classify incidents by severity and follow a documented response process with defined acknowledgement and update cadences. Affected customers are notified through email and our status page, and a post-incident report is shared for major incidents.

SeverityDefinitionAcknowledgeUpdate cadence
P1 — CriticalPlatform-wide outage or data-integrity risk15 minEvery 30 min
P2 — HighSignificant degradation or single-component failure30 minHourly
P3 — MediumLimited impact with a workaround available4 business hrsDaily

Business continuity & disaster recovery

Critical components are redundant and fail over automatically. We maintain a documented disaster-recovery plan covering data-store recovery, compute replacement, and regional failure, and we test recovery procedures on a regular schedule. Recovery objectives are defined per scenario as shown above.

Backups & data retention

DataMethodRetention
Customer & assessment dataAutomated point-in-time backupsConfigurable; default 30 days
Candidate work productEncrypted storagePer customer configuration & DPA
Application configurationVersion controlledIndefinite
LogsCentralized aggregationDefined retention window

All backups are encrypted at rest. Customers can request deletion of candidate data in accordance with their agreement.

Vulnerability management & testing

We patch systems on a regular cadence, scan for vulnerabilities, and engage independent third parties for periodic penetration testing. Findings are tracked to remediation. We run a responsible-disclosure process; report any suspected vulnerability to info@buildersalpha.com.

Contact & documentation requests

For our SOC 2 report, penetration-test summary, DPA, subprocessor list, or a completed security questionnaire, contact info@buildersalpha.com or reach out through our contact form. See also our Subprocessors and Privacy Policy pages.

Need our security package?

We'll share our SOC 2 report, DPA, and answer your security questionnaire under NDA.