LEGAL & COMPLIANCE

Security Center

How we protect your data and projects with enterprise-grade security.

Last Updated: August 2026

1. Our Security Approach

At Core BIM Solutions, we understand that your building models, intellectual property, and project plans are highly sensitive. We treat your data with the same rigorous security protocols that we apply to our own infrastructure, employing a defense-in-depth approach across our entire technology stack.

2. Infrastructure & Hosting Security

We utilize top-tier, enterprise-grade cloud providers to ensure maximum reliability and security:

  • Vercel Edge Network: Our website and backend services run on Vercel's highly secure, SOC2 compliant edge infrastructure.
  • Cloudflare Security: We leverage Cloudflare for DNS management, SSL/TLS encryption (HTTPS), DDoS mitigation, and advanced Web Application Firewall (WAF) protection.
  • Strict Security Headers: Our application enforces strict Content Security Policies (CSP) and HTTP Strict Transport Security (HSTS) to prevent unauthorized script execution and man-in-the-middle attacks.

3. Data Protection & Transmission

All data transmitted between your browser and our servers is encrypted in transit using industry-standard TLS 1.3. We do not store sensitive payment information directly; instead, we rely on established B2B invoicing standards and verified financial partners. Project files and CAD/BIM assets are transferred using secure, encrypted file-sharing platforms.

4. Form & API Protection

Our lead generation and contact systems are heavily fortified against abuse, spam, and malicious payloads. We utilize Cloudflare Turnstile for privacy-friendly bot detection, combined with custom server-side heuristics (including timing analysis, payload size limits, and cryptographic token verification) to ensure our communications infrastructure remains secure and performant.

5. Responsible Disclosure

We take security research seriously. If you believe you have discovered a vulnerability on our website or within our systems, we ask that you disclose it to us responsibly.

  • Please do not exploit the vulnerability (e.g., by downloading more data than necessary or deleting data).
  • Please report the issue to us securely via email at info@corebimsolutions.com.
  • We will acknowledge your report promptly and work to resolve the issue in a timely manner.

For more automated discovery, you can reference our security.txt file.