Security at Exayard
How we protect your plans, pricing, and project data — and how agents and integrations are authorized to access them.
Encryption
Data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256. Plan PDFs, takeoff measurements, and product pricing are encrypted at the storage layer.
Authentication
Identity is managed through Clerk. We support email/password, Google, Microsoft, and SAML SSO for Enterprise. Multi-factor authentication is available on all paid tiers.
Roles and access control
Every workspace has two organization roles. Admins manage the team, invitations, billing, and organization settings, while members do the everyday takeoff and estimating work. To share work outside your workspace, you grant someone viewer access (view and comment) or editor access (make changes) to a single project, never your whole account. All of these checks run on our servers, so the interface cannot be bypassed to gain access a role does not allow.
API keys and OAuth
API keys carry an explicit scope list (read/write per resource). OAuth follows RFC 7591 Dynamic Client Registration so registered MCP clients (Claude, Cursor, etc.) get tokens via the protected-resource discovery endpoint. Least-privilege by default.
Audit logs
Every request carries an X-Request-Id. Agent identity is preserved through OAuth client IDs so audit logs distinguish "Claude Desktop acting for alice" from "alice directly."
Webhooks
Outbound webhooks are signed with HMAC-SHA256. Signatures include a timestamp and reject deliveries older than 5 minutes. Endpoint secrets are returned only at creation time.
Data residency
Production data is hosted in the United States on infrastructure providers that maintain SOC 2 Type II certifications. Enterprise customers can request specific data residency options.
Vulnerability disclosure
Report security issues to security@exayard.com. We acknowledge reports within 1 business day and target a fix within 30 days for high-severity findings. We do not pursue researchers acting in good faith.
Compliance
GDPR-aligned data handling, with a Data Processing Addendum available for business customers. Our infrastructure providers maintain SOC 2 Type II certifications. HIPAA is not currently supported.
Account deletion
You can delete projects and your entire account from settings at any time. Backups are retained for 30 days post-deletion to support disaster recovery, after which all data is permanently erased.
Sub-processors
These providers handle customer data on our behalf. We notify customers before adding new sub-processors that handle customer data.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Hosting and AI gateway | United States |
| Convex | Database and backend | United States |
| Cloudflare | File storage and delivery | United States (global network) |
| Anthropic | AI models | United States |
| OpenAI | AI models | United States |
| Clerk | Authentication | United States |
| Stripe | Payments | United States |
| Intercom | Customer support | United States |
| Sentry | Error tracking | United States |
| PostHog | Product analytics | United States |
| Analytics and advertising | United States |
Last reviewed: July 2026
Ready to win more bids?
Use Exayard to estimate faster and win more work. Get started today.