System · Operational
EAT · 14:27
§ SLegal · Buildra

Security & Compliance

Buildra is trusted to hold evidence that people rely on. This page summarises how we protect data and evidence, and where we stand on independent assurance.

Last updated · 23 June 2026
01

Overview

Security is built into the product, not bolted on. Evidence is sealed and stored write-once, data is encrypted, access is least-privilege and logged, and our infrastructure runs with reputable cloud providers. We review our controls regularly as we grow.

02

Data protection

  • Encryption in transit using current TLS for all connections.
  • Encryption at rest for stored data and media.
  • Secrets management for keys and credentials, separated from application code.
  • Backups taken on a regular schedule and tested for recovery.
03

Evidence integrity

Each exhibit is bound to a SHA-256 hash, a dual timestamp and GPS metadata, and written to write-once storage so originals cannot be overwritten. Hashes are anchored on a schedule, and every access is recorded in the chain of custody. See the Evidence Policy for detail.

04

Access control

  • Role-based access within each customer organisation.
  • Single sign-on (SSO) available on eligible plans, and strong authentication for staff.
  • Least-privilege internal access; staff access to customer evidence is limited to operating, supporting or securing the Service, and is logged.
05

Infrastructure

The Service runs on established cloud infrastructure with isolation between environments and managed network controls. Where feasible we use regions appropriate for our Tanzanian customers, and write-once object storage for sealed evidence.

06

Monitoring & response

We log system and security events, monitor for anomalies, and maintain an incident-response process. If a security incident affects your data, we will act to contain it and notify affected customers and, where required, the Personal Data Protection Commission, in line with the Personal Data Protection Act, 2022.

07

Compliance posture

We design our controls to align with recognised frameworks, including ISO/IEC 27001, and we are working towards a SOC 2 Type II examination. We are happy to share our current security documentation and status under NDA on request. We process personal data in accordance with the Personal Data Protection Act, 2022 of Tanzania — see our Privacy Policy.

08

Reporting a vulnerability

We welcome responsible disclosure. If you believe you have found a security issue, please email security@buildra.co.tz with enough detail to reproduce it. Please give us reasonable time to investigate and fix the issue before any public disclosure, and do not access or modify data that is not yours.

09

Contact

Security team: security@buildra.co.tz · Buildra Systems Ltd, Rose Garden Rd, Mikocheni, Dar es Salaam, Tanzania.

Questions about this policy? Write to legal@buildra.co.tz. See also our Privacy Policy, Terms of Service, Evidence Policy and Security & Compliance pages.