Security Addendum
Updated August 19, 2026
This Security Addendum describes the technical and organizational measures Builder.io, Inc. ("Builder") has designed to protect Customer Data. It is incorporated into the SaaS Services Agreement and the Data Processing Addendum, and serves as Annex II to the EU Standard Contractual Clauses. Builder may update these measures provided the updates do not materially reduce the overall level of security.
1. Security Program and Governance
Builder maintains a documented information-security program with policies reviewed at least annually. Builder maintains a SOC 2 Type 2 examination covering the Services. A current report is available to customers under NDA on request.
2. Access Control
- Role-based access control and least-privilege principles for systems processing Customer Data.
- Unique user accounts; no shared credentials for production access.
- Multi-factor authentication required for production systems and administrative interfaces.
- Access reviews performed at least quarterly and on role change or termination.
3. Encryption
- Customer Data in transit encrypted using TLS 1.2 or higher.
- Customer Data at rest encrypted using AES-256.
- Key management performed using a managed key-management service with restricted access.
4. Network and Infrastructure Security
- Segmentation between production, staging, and corporate environments.
- Firewalls and security groups restricting traffic to what is required.
- Hardened configurations and timely patching of infrastructure components.
- Logging and monitoring of access to and activity within production systems, with alerting on anomalous activity.
5. Application Security
- Secure development practices, including code review and dependency management.
- Vulnerability management, including regular scanning and timely remediation by severity.
- Penetration testing performed at least annually by a qualified third party. Summary results available to customers under NDA on request.
6. Personnel Security
- Background checks for personnel with access to Customer Data, where permitted by law.
- Confidentiality obligations for all personnel.
- Security-awareness training at onboarding and at least annually.
7. Incident Response
- Builder maintains an incident response plan designed to cover detection, containment, eradication, and recovery.
- Customers are notified of confirmed personal data breaches within seventy-two (72) hours of Builder becoming aware.
- Post-incident reviews are conducted to identify root cause and prevent recurrence.
8. Business Continuity and Disaster Recovery
- Builder maintains BC/DR plans tested at least annually.
- Recovery Time Objective (RTO): 4 hours. Recovery Point Objective (RPO): 24 hours.