Security
We take the security of your data seriously. This page describes how we protect your information and the measures we have in place to keep it safe.
Last updated: 2026-05-01
Security Features
Encryption in Transit
All data transmitted between your browser and our servers is encrypted using TLS 1.3.
Encryption at Rest
Cloud-synced data is encrypted using AES-256 encryption before storage.
Local-First Architecture
Your data stays on your device by default. Cloud sync is opt-in.
Secure Authentication
Industry-standard authentication with optional two-factor authentication.
Access Controls
Role-based permissions ensure team members see only what they need.
Audit Logging
Changes to your data are logged for accountability and troubleshooting.
Local-First Security
SiteCAD uses a local-first architecture that keeps your data under your control:
- Data stays on your device — Your sites and designs are stored in your browser's IndexedDB by default. They never leave your computer unless you choose to enable cloud sync.
- Works offline — Because your data is local, you can work without an internet connection. Changes sync when you're back online.
- No account required — You can use SiteCAD's core features without creating an account or sharing any personal information.
- Export anytime — You can always export your data in standard formats, ensuring you're never locked in.
Security Practices
Infrastructure Security
- Hosted on major cloud infrastructure providers that hold SOC 2 certification
- Network isolation and firewall protection
- Regular security patching and updates
- Automated vulnerability scanning
- DDoS protection
Application Security
- Secure development practices and code review
- Input validation and output encoding
- Protection against common vulnerabilities (OWASP Top 10)
- Regular dependency updates
- Content Security Policy (CSP) headers
Data Protection
- Automated backups with point-in-time recovery
- Geographic redundancy for disaster recovery
- Data minimization — we collect only what's needed
- Secure data deletion when requested
- Export capability for data portability
Operational Security
- Principle of least privilege for employee access
- Security awareness training
- Incident response procedures
- Regular security assessments
- Vendor security review
Compliance
GDPR
We comply with the General Data Protection Regulation for users in the European Economic Area. This includes data minimization, purpose limitation, and honoring data subject rights.
CCPA
We comply with the California Consumer Privacy Act, including the right to know what data is collected and the right to deletion.
SOC 2 Roadmap
We are working toward SOC 2 Type II certification. Our infrastructure providers are already SOC 2 certified.
Security Reporting
Responsible Disclosure
We appreciate the security research community and welcome reports of potential vulnerabilities. If you discover a security issue, please report it responsibly.
How to Report
- Email: security@sitecad.com
- Include a detailed description of the vulnerability
- Provide steps to reproduce if possible
- Do not publicly disclose until we've had time to address the issue
What to Expect
- Acknowledgment of your report within 48 hours
- Regular updates on our investigation and remediation progress
- Credit for the discovery (if desired) after the issue is resolved
- We do not pursue legal action against researchers acting in good faith
Security FAQ
Is my data encrypted?
Yes. Data transmitted to our servers is encrypted using TLS 1.3. If you enable cloud sync, your data is also encrypted at rest using AES-256 encryption.
Who can access my data?
Only you and team members you explicitly grant access to. Our employees do not access customer data except when required for support (with your permission) or legal compliance.
What happens if there's a data breach?
We have incident response procedures in place. In the event of a breach affecting your data, we will notify you within 72 hours with details about what happened and what we're doing about it.
Can I use SiteCAD without cloud sync?
Yes. SiteCAD works entirely locally without an account. Your data stays in your browser and never touches our servers. Cloud sync is an optional feature for registered users.
Do you use AI, and is my data used to train models?
SiteCAD uses AI for the assistant feature. Your data is sent to LLM providers only when you interact with the assistant. We do not use your site data to train AI models. See our for details.
How do you handle third-party dependencies?
We regularly audit and update third-party dependencies. We use automated tools to detect known vulnerabilities and maintain a software bill of materials (SBOM) for tracking.
Questions?
If you have questions about our security practices or want to discuss security requirements for your organization, contact us.
Digithought LLC — Security Team
Email: security@sitecad.com