Security & Trust Center

At Forensic BIM, protecting your data is our highest priority. Explore our comprehensive approach to security, privacy, and compliance.

NIST CSF 2.0 Alignment

Our comprehensive security program is designed and maintained in strict alignment with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0. We employ a defense-in-depth strategy covering all six core functions:

Govern & Identify

We maintain strict vendor risk management, enforce regional data residency, and continuously assess our infrastructure for emerging threats to protect your critical assets.

Protect

Operating under a Zero Trust architecture, all user data is tenant-isolated. Uploaded IFC files undergo SHA-256 cryptographic verification, and all compute environments operate with the principle of least privilege.

Detect

Our platform leverages continuous, multi-layer automated vulnerability scanning (including SAST, DAST, and dependency checks) alongside tamper-proof, immutable audit logging.

Respond & Recover

We maintain rigorously tested Incident Response and Disaster Recovery plans, ensuring business continuity and rapid resilience in the event of an anomaly.

SOC 2 Type II and ISO 27001 Standards

🛡️ Built to SOC 2 Type II Standards 🔒 Built to ISO 27001 Standards

Our infrastructure and internal policies are designed in strict accordance with SOC 2 Type II and ISO 27001 standards. We currently operate under these rigorous internal controls, including multi-factor authentication (MFA) requirements, 60-minute session idle timeouts, data encryption at rest and in transit, and continuous compliance-as-code automation. We are actively operating these controls in preparation for our formal third-party audit and certification.

GDPR Compliance & Privacy

Forensic BIM is fully compliant with the General Data Protection Regulation (GDPR). We are committed to protecting your personal data and ensuring you have complete control over your information. We enforce data minimization, provide a comprehensive "Right to Erasure" (allowing you to permanently delete all your analysis and models), and offer 8 distinct regional sovereignty hubs so your data never leaves your chosen geographic region.

For more detailed information on how we handle and protect your personal data, please review our comprehensive Privacy Policy.