Security at Brad

Brad holds the documents that run your project: plans, contracts, change orders, invoices, photos, and conversations. That is sensitive material, and how it is stored, who can reach it, and what happens to it matters. This page states plainly what is true today, and is clear about the things we are still building. For specifics on your engagement, ask us directly when you join the waitlist.

Encryption, in transit and at rest

Connections that carry your project’s data are encrypted in transit: Brad reaches its database, file storage, and AI providers over TLS (HTTPS).

Your documents come to rest in managed cloud infrastructure that encrypts data at rest with AES-256: our database and file storage run on Supabase (Postgres and Storage, encrypted at rest by default), and inbound channel attachments and files from sources you connect are stored in Cloudflare R2 (encrypted at rest with AES-256). We rely on these providers’ platform encryption for the stores that hold your documents rather than rolling our own.

Access and workspace isolation

A project’s information is reachable by the people who belong to that workspace, plus anyone you deliberately share a specific document with through a share link, at the access level you choose. Workspaces are isolated from one another at the database level: the project tables that hold your data are fenced by row-level security tied to your workspace membership, and the application’s write paths additionally check that the person making a change belongs to the workspace they’re changing. One workspace cannot read another’s records by asking; a cross-workspace lookup simply returns nothing.

Access follows workspace membership and the share links you create. Remove someone from a workspace, or revoke a share link, and their reach changes with it.

Roles and permissions

Inside a workspace, access follows four clear customer roles: Owner, Manager, Staff, and Viewer. Viewers have read-only project and Ask BRAD access. Staff handle daily project work such as uploads, corrections, comments, and updates. Managers additionally manage projects, sharing, approvals, Staff, and Viewers. Owners have full workspace control, including Managers, billing, integrations, and security settings.

Owners can adjust role capability templates within invariant guardrails, so access can be tightened for a role without one-off personal permissions. Permissions are also bounded by your plan: a capability your plan doesn’t include can’t be enabled. Demote someone, change the role template, or downgrade the plan, and their access narrows immediately. Brad’s site administrators are a separate platform-operator allowlist, not a customer workspace role.

Public pages vs. your signed-in workspace

This site has a clear, enforced boundary. The public marketing pages, including the one you’re reading, the use-case pages, and the learn library, require no sign-in and contain no customer project data; a request for an app page from someone who isn’t signed in is redirected to sign-in.

The only ways into a project’s data are signing in to your workspace or opening a share link you were explicitly sent, never one of these public marketing pages.

AI providers: we don’t train public models on your data

Brad’s answers are generated by reading your documents with established AI providers (OpenAI and Anthropic) through their metered business APIs. Inputs and outputs sent through those APIs are not used to train the providers’ public models; that is their standard API policy. Our system is built to enforce this: it is configured so that customer inference routes only through these metered API keys, with a startup check that refuses to run a production deployment serving customer traffic that isn’t in that mode, so a consumer subscription path can’t be used for your data.

Your project content is yours. We do not sell it, and we do not use it to train any general-purpose model.

Who we share data with (subprocessors)

Brad runs on a small set of established providers, each used for a specific purpose. Vercel hosts the application and edge that serve Brad: your requests pass through it and some upload and attachment traffic transits its functions, though it isn’t the persistent store for your documents. Supabase hosts our database, file storage, and authentication (your documents, accounts, and workspace data). OpenAI and Anthropic provide the AI inference that reads your documents and generates answers, and an embeddings provider (such as Voyage, OpenAI, or Google) turns your documents into the vectors that power search. Cloudflare provides edge infrastructure, Email Routing for inbound project email, R2 object storage for inbound attachments and files from sources you connect, and signup bot-protection. Stripe handles billing (account and payment metadata, not your project documents). Inngest runs our background document-processing jobs. Twilio powers phone verification for sign-in. Resend and, when configured, AgentMail carry outbound transactional and notification email.

The full, dated list, with each provider, its purpose, and the data it touches, lives on our subprocessors page, and you can ask us for a formal copy for a procurement review.

Backups

Brad’s system of record is its Supabase database, the connected record we build from your project, and it takes automated daily backups. The original uploaded files live in Supabase Storage and Cloudflare R2; the inbound attachments we stage in R2 can be reprocessed from source, and the fast-read graph projection is rebuilt from the database.

We’re still formalizing the rest: backup of the stored file objects, a tested restore drill, and stated recovery targets (how recent a backup you’d recover from, and how fast a restore completes) are on our list, and we’ll publish those once we’ve measured them rather than guess.

Incident response

We maintain an incident-response process. If something goes wrong, whether a security issue or a problem affecting your data, we triage it by severity, contain it first, fix the root cause (restoring from backup if needed), and notify the affected workspaces with what happened, what data was involved, and what we did. Every significant incident gets a written post-mortem in our internal log.

We describe the process here rather than promise a specific notification deadline. If your organization needs a committed timeframe in writing, ask us and we’ll tell you what we can commit to.

Staff access

Access by our own team follows least privilege. The ability to reach across workspaces, meaning our internal operations console and global settings, is limited to a small, explicit operator allowlist enforced in the database; it isn’t ambient, and it’s separate from your workspace’s own roles.

We’re still building the formal piece: a unified log of staff access and a regular review to confirm that list stays current. We’d rather tell you that’s in progress than imply a maturity we haven’t reached.

Audit log

Workspace members can export a timestamped audit log of permitted activity — document uploads, human corrections, compliance state changes, and share-link accesses. The log is scoped strictly to your own workspace: operator-internal and cross-workspace events are excluded. It is available on Builder and higher plans.

Staff and Managers receive their own activity; Owners with the export capability receive the full workspace log and can download it as CSV or JSON.

Admin security controls and workspace deletion

Owners and Managers manage the members below their level from Account → Team: Owners can manage Managers, Staff, and Viewers; Managers can manage Staff and Viewers. Owners and admins can revoke API keys; workspace deletion remains owner-only. API-key revocation takes immediate effect, so any in-flight request using a revoked key fails on its next authentication check.

Workspace owners can delete the workspace themselves from Account → Settings → Security. Deletion is irreversible: it permanently removes all documents, members, API keys, and the graph record built from your data (including file-storage bytes and the fast-read graph projection). If the workspace has an active Stripe subscription, Brad attempts to cancel it during deletion; Stripe customer, invoice, and subscription history may be retained for accounting and tax purposes and does not contain project-document content. The control requires the owner to type the exact workspace name; the server enforces that check and the owner-only role independently, not just as a UI affordance.

What we’re still building

We’d rather tell you exactly where we are than imply a certification we haven’t earned. In progress: a formal privacy policy and data-processing agreement (DPA) for enterprise, staff-access review, and formalizing our backup/restore process (file-object backup, restore drill, and stated RPO/RTO).

We have not pursued a formal compliance certification such as SOC 2, and we won’t claim one until we have it. If your organization needs documentation of specific controls before adopting a tool, contact us and we will tell you plainly what we can and cannot provide.

The scope of this page

This page describes what is true today and what is underway, not a list of guarantees or certifications. Brad assists with construction document intelligence. It does not replace licensed professional judgment, legal review, or your obligations under your contracts.

See Brad on your project

Brad connects the plans, contracts, change orders, photos, and conversations on your job into one source of truth. Join the waitlist and bring a project you want to untangle.

Join the waitlist