Your event data is in safe hands
BuilderBase is built to protect organizer, sponsor, and participant data at every stage of an event, from application to post-event reporting.
- TLS encryption
- EU data residency
- Role-based access
What runs under your events.
- GDPR aligned*
- Encryption at rest*
- Encryption in transit
- EU data residency
- Infrastructure providers*
- Infrastructure providers*
- Per-organization data
- Organizer & admin tools*
SOC 2 and ISO 27001 certifications are held by our infrastructure providers, Cloudflare and Supabase. BuilderBase is not yet independently certified.
- GDPR — We build to GDPR principles and operate from the EU. There is no certification to hold against GDPR — this is alignment, not an audit result.
- 256-bit AES — Applied by our infrastructure providers on the storage layer, not implemented by BuilderBase.
- SOC 2 Type II — Held by Cloudflare and Supabase. BuilderBase is not itself SOC 2 certified.
- ISO 27001 — Held by Cloudflare and Supabase. BuilderBase is not itself ISO 27001 certified.
- Role-based access — Roles are coarse today. Granular, tiered permissions are on the roadmap.
Still being built: we do not yet run a formal, structured risk management program, our incident response is not yet documented with defined response timelines, and onboarding, offboarding, and confidentiality processes are still being formalized as the team grows. We are happy to talk through any of it.
We keep your event data safe.
Isolation by default, least privilege on access, encryption on the wire.
Data protection
Every event on BuilderBase runs in its own isolated space. Applications, submissions, judging scores, and sponsor information are separated by organization, so one event’s data is never exposed to another.
Controlled access & encryption
Access to organizer and admin tools is role-based. API access is scoped to specific routes rather than broad account-level permissions, so a compromised key cannot reach more than it needs to. Data is encrypted in transit, and our infrastructure providers encrypt data at rest.
We keep your event data private.
Where your data lives, who can reach it, and what we will never do with it.
- 01
GDPR aligned
BuilderBase is built and operated from Stockholm with GDPR principles at the center of how we handle personal data.
- 02
No AI training on your data
We do not use event, applicant, or submission data to train foundation AI models, and we do not share it with external vendors for that purpose.
- 03
Regional hosting
Your data is stored in EU-based data centers in Ireland, supporting EU data residency requirements.
- 04
Independently certified infrastructure
BuilderBase itself is not yet SOC 2 or ISO 27001 certified. Our underlying infrastructure providers, Cloudflare and Supabase, are independently certified to SOC 2 and ISO 27001, and we build on top of that foundation.
Enterprise security review? We will complete your questionnaire and walk your team through our current controls. Email us.



Security questions, answered plainly.
Including the parts we are still building.
How do you uphold information security?
How do you control access to your systems?
How do you manage risk?
How do you secure operations?
How do you uphold security with your team?
Do you use our data to train AI models?
What happens if there is a security incident?
Need a deeper review?
We will sit down with your security team, answer the questionnaire, and be straight about what is in place today and what is on the roadmap.