Security at Exayard

How we protect your plans, pricing, and project data — and how agents and integrations are authorized to access them.

Encryption

Data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256. Plan PDFs, takeoff measurements, and product pricing are encrypted at the storage layer.

Authentication

Identity is managed through Clerk. We support email/password, Google, Microsoft, and SAML SSO for Enterprise. Multi-factor authentication is available on all paid tiers.

Roles and access control

Every workspace has two organization roles. Admins manage the team, invitations, billing, and organization settings, while members do the everyday takeoff and estimating work. To share work outside your workspace, you grant someone viewer access (view and comment) or editor access (make changes) to a single project, never your whole account. All of these checks run on our servers, so the interface cannot be bypassed to gain access a role does not allow.

API keys and OAuth

API keys carry an explicit scope list (read/write per resource). OAuth follows RFC 7591 Dynamic Client Registration so registered MCP clients (Claude, Cursor, etc.) get tokens via the protected-resource discovery endpoint. Least-privilege by default.

Audit logs

Every request carries an X-Request-Id. Agent identity is preserved through OAuth client IDs so audit logs distinguish "Claude Desktop acting for alice" from "alice directly."

Webhooks

Outbound webhooks are signed with HMAC-SHA256. Signatures include a timestamp and reject deliveries older than 5 minutes. Endpoint secrets are returned only at creation time.

Data residency

Production data is hosted in the United States on infrastructure providers that maintain SOC 2 Type II certifications. Enterprise customers can request specific data residency options.

Vulnerability disclosure

Report security issues to security@exayard.com. We acknowledge reports within 1 business day and target a fix within 30 days for high-severity findings. We do not pursue researchers acting in good faith.

Compliance

GDPR-aligned data handling, with a Data Processing Addendum available for business customers. Our infrastructure providers maintain SOC 2 Type II certifications. HIPAA is not currently supported.

Account deletion

You can delete projects and your entire account from settings at any time. Backups are retained for 30 days post-deletion to support disaster recovery, after which all data is permanently erased.

Sub-processors

These providers handle customer data on our behalf. We notify customers before adding new sub-processors that handle customer data.

ProviderPurposeLocation
VercelHosting and AI gatewayUnited States
ConvexDatabase and backendUnited States
CloudflareFile storage and deliveryUnited States (global network)
AnthropicAI modelsUnited States
OpenAIAI modelsUnited States
ClerkAuthenticationUnited States
StripePaymentsUnited States
IntercomCustomer supportUnited States
SentryError trackingUnited States
PostHogProduct analyticsUnited States
GoogleAnalytics and advertisingUnited States

Last reviewed: July 2026

Security questions?

For vendor assessments or DPAs, contact our team.

Contact us

Ready to win more bids?

Use Exayard to estimate faster and win more work. Get started today.