Security Architecture & Data Protection

How SmartX Construction Technologies protects SmartX and MeasureX AI across infrastructure, application layers, and AI processing pipelines.

Encryption

TLS 1.3 & AES-256

Encrypted in transit and at rest across storage & database.

Tenancy

Strict Multi-Tenant Isolation

Role-scoped access control per company & project assignment.

AI Privacy

Zero Model Training

Customer blueprints are never ingested into training corpuses.

Resilience

Point-in-Time Recovery

Automated rolling snapshots & multi-region asset caching.

1. Security Philosophy

Construction blueprints, tender specifications, bill of quantities (BOQ), and proprietary estimating unit rates represent critical commercial assets for contractors, engineers, and developers.

SmartX designs every layer of MeasureX AI using a Defense-in-Depth security model. We enforce principle-of-least-privilege access, zero-trust network policies, cryptographic session validation, and strict isolation between partner company workspaces.

2. Infrastructure & Network Security

  • Encryption in Transit: All HTTP traffic to https://www.smartxcc.com and backend APIs is strictly enforced over HTTPS using TLS 1.3 with modern cipher suites. HTTP Strict Transport Security (HSTS) is enabled with preload directives.
  • Encryption at Rest: Customer drawings, page previews, and rendered tile artifacts stored in Cloudflare R2 object storage are encrypted using AES-256 encryption. Database storage partitions utilize encrypted volumes.
  • DDoS & Web Application Firewall (WAF): Edge infrastructure provides automated distributed denial-of-service mitigation, rate limiting, and intelligent bot filtering to protect platform availability.
  • Isolated Database Network: Relational database instances communicate via isolated UNIX domain sockets and private network interfaces, completely unexposed to the public internet.

3. Authentication, Session & Access Control

  • Cryptographic Session Tokens: Authenticated sessions use HMAC-SHA256 signed tokens stored in hardened `HttpOnly`, `SameSite=Lax`, `Secure` cookies, preventing cross-site scripting (XSS) token exfiltration.
  • Password Protection: Passwords are hashed using the memory-hard scrypt key derivation function with unique cryptographic salts. Passwords are never stored, logged, or retrievable in plaintext.
  • Role-Based Access Control (RBAC): Access is strictly segregated by organizational role:
    • Platform Administrator: Platform monitoring, seat allocation, and global audit logging.
    • Company Manager: Workspace user invitations, subscription management, and company-wide project governance.
    • Estimator: Markup, measurement, takeoff generation, and schedule extraction on assigned drawings.
    • Customer / Client Portal: Sandboxed view-only access on delivered project revisions without markup edit permissions.
  • Idle Session Guard & Global Logout: Inactivity timeouts automatically lock dormant sessions. Global logout commands immediately increment the user’s session version, invalidating all outstanding tokens across all active devices.

4. Application Security & Hardening

  • Content Security Policy (CSP): HTTP headers enforce strict script, style, and frame boundaries, mitigating clickjacking (X-Frame-Options: DENY), MIME-sniffing, and cross-site scripting risks.
  • Input Sanitization & Safe CAD Parsing: Drawing uploads (PDF, DWG, DXF, PNG, JPG, WebP) undergo rigorous format validation and bounded memory rendering to prevent buffer overflow or parser exploit vectors.
  • Layer & Project Level Tenancy Enforcement: All API endpoints enforce double-validation: verifying the user’s authenticated company scope against the requested takeoff record before executing read or write operations.
  • Rate Limiting & Concurrency Throttling: API rate limiters protect login routes, upload streams, and AI processing queues from brute-force or resource starvation attempts.

5. AI Pipeline & Customer Drawing Privacy

MeasureX AI features automated symbol takeoff, scale calibration, schedule OCR, and AI Helper workflows. We enforce strict data privacy standards across our AI pipelines:

  • No Model Training: Your uploaded drawings, takeoff markups, and project quantities are never used to train, fine-tune, or improve public or proprietary foundation models.
  • Ephemeral Vision Processing: AI vision analysis runs ephemerally in memory within private compute slots. Once feature extraction is completed, the vision payload is purged from the processing queue.
  • Enterprise AI Infrastructure: Cloud vision endpoints are contracted under enterprise terms featuring strict zero-data-retention, encrypted transit, and non-disclosure guarantees.

6. Data Continuity, Backups & Disaster Recovery

  • Automated Database Snapshots: Encrypted database snapshots are automatically generated and preserved with point-in-time recovery capabilities.
  • Admin Recovery Portal: Authorized company administrators have access to snapshot recovery tools to restore prior takeoff revisions in the event of accidental user deletions.
  • High-Availability Cloud Storage: Drawing source files and rendered image pyramids are stored in geographically replicated cloud object storage with 99.999999999% (11 9s) durability.

7. Vulnerability Management & Responsible Disclosure

We appreciate the contributions of security researchers and practitioners who help us maintain the highest safety standards. If you discover a potential vulnerability within the SmartX platform:

  • Reporting Email: security@smartxcc.com
  • Security Contact File: /.well-known/security.txt
  • Guidelines: Please provide a detailed description of the issue, reproduction steps, and allow reasonable time for remediation before public disclosure. We do not pursue legal action against researchers acting in good faith.

8. Contact & Security Compliance Inquiries

For enterprise security questionnaires, vendor assessments, or compliance documentation, please reach out to our team: