We take the safety of your data seriously. Here is what we do, and how to tell us if we missed something.
How we protect data
- All traffic to our sites and portals is encrypted with HTTPS.
- Passwords are stored only as strong one-way hashes and are never emailed after the first sign-in.
- Customer data is separated by account, and every request is checked server-side.
- Sign-in attempts are rate limited and accounts lock after repeated failures.
- Staff get only the access their role needs, and sensitive actions are logged.
- We keep dependencies patched and use reputable infrastructure providers.
Reporting a vulnerability
If you believe you have found a security issue in builderve.com, the client portal or another Builderve system, please email customer@builderve.com with the details and steps to reproduce it. We will acknowledge your report within 3 working days and keep you informed.
Please:
- give us reasonable time to fix the issue before sharing it publicly;
- avoid accessing, changing or deleting data that is not yours, and stop as soon as you have shown the problem;
- not run denial-of-service, spam or social-engineering tests against our staff or customers.
If you act in good faith and follow these rules, we will not take legal action against you. We do not run a paid bug-bounty programme, but we are glad to credit you if you wish.
If something goes wrong
If a security incident affects your data, we will tell you promptly, explain what happened and what we are doing about it, and notify the authorities where the law requires.

