Security Features

Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.3.

Encryption at Rest

Cloud-synced data is encrypted using AES-256 encryption before storage.

Local-First Architecture

Your data stays on your device by default. Cloud sync is opt-in.

Secure Authentication

Industry-standard authentication with optional two-factor authentication.

Access Controls

Role-based permissions ensure team members see only what they need.

Audit Logging

Changes to your data are logged for accountability and troubleshooting.

Local-First Security

SiteCAD uses a local-first architecture that keeps your data under your control:

  • Data stays on your device — Your sites and designs are stored in your browser's IndexedDB by default. They never leave your computer unless you choose to enable cloud sync.
  • Works offline — Because your data is local, you can work without an internet connection. Changes sync when you're back online.
  • No account required — You can use SiteCAD's core features without creating an account or sharing any personal information.
  • Export anytime — You can always export your data in standard formats, ensuring you're never locked in.

Security Practices

Infrastructure Security

  • Hosted on major cloud infrastructure providers that hold SOC 2 certification
  • Network isolation and firewall protection
  • Regular security patching and updates
  • Automated vulnerability scanning
  • DDoS protection

Application Security

  • Secure development practices and code review
  • Input validation and output encoding
  • Protection against common vulnerabilities (OWASP Top 10)
  • Regular dependency updates
  • Content Security Policy (CSP) headers

Data Protection

  • Automated backups with point-in-time recovery
  • Geographic redundancy for disaster recovery
  • Data minimization — we collect only what's needed
  • Secure data deletion when requested
  • Export capability for data portability

Operational Security

  • Principle of least privilege for employee access
  • Security awareness training
  • Incident response procedures
  • Regular security assessments
  • Vendor security review

Compliance

GDPR

We comply with the General Data Protection Regulation for users in the European Economic Area. This includes data minimization, purpose limitation, and honoring data subject rights.

CCPA

We comply with the California Consumer Privacy Act, including the right to know what data is collected and the right to deletion.

SOC 2 Roadmap

We are working toward SOC 2 Type II certification. Our infrastructure providers are already SOC 2 certified.

Shared Responsibility Model

Platform security is not the same as regulatory compliance for your designs. The practices and certifications described above cover how we protect the SiteCAD platform and the data you store in it. They do not certify, approve, or warrant the regulatory fitness, lawfulness, or engineering correctness of anything you design, calculate, export, publish, or construct using the Service.

You are solely responsible for ensuring that your use of the Service, your designs, and your constructed outcomes comply with all applicable laws, regulations, codes, permits, and professional-licensure requirements in the jurisdictions where the work will be used or built. Independent review by appropriately licensed professionals is required before relying on any Service output for permitting, construction, legal filing, or financial decisions. See the for the full allocation of compliance responsibility.

Security Reporting

Responsible Disclosure

We appreciate the security research community and welcome reports of potential vulnerabilities. If you discover a security issue, please report it responsibly.

How to Report

  • Email: security@sitecad.com
  • Include a detailed description of the vulnerability
  • Provide steps to reproduce if possible
  • Do not publicly disclose until we've had time to address the issue

What to Expect

  • Acknowledgment of your report within 48 hours
  • Regular updates on our investigation and remediation progress
  • Credit for the discovery (if desired) after the issue is resolved
  • We do not pursue legal action against researchers acting in good faith

Security FAQ

Is my data encrypted?

Yes. Data transmitted to our servers is encrypted using TLS 1.3. If you enable cloud sync, your data is also encrypted at rest using AES-256 encryption.

Who can access my data?

Only you and team members you explicitly grant access to. Our employees do not access customer data except when required for support (with your permission) or legal compliance.

What happens if there's a data breach?

We have incident response procedures in place. In the event of a breach affecting your data, we will notify you within 72 hours with details about what happened and what we're doing about it.

Can I use SiteCAD without cloud sync?

Yes. SiteCAD works entirely locally without an account. Your data stays in your browser and never touches our servers. Cloud sync is an optional feature for registered users.

Do you use AI, and is my data used to train models?

SiteCAD uses AI for the assistant feature. Your data is sent to LLM providers only when you interact with the assistant. We do not use your site data to train AI models. See our for details.

How do you handle third-party dependencies?

We regularly audit and update third-party dependencies. We use automated tools to detect known vulnerabilities and maintain a software bill of materials (SBOM) for tracking.

Questions?

If you have questions about our security practices or want to discuss security requirements for your organization, contact us.

Digithought LLC — Security Team
Email: security@sitecad.com