Enterprise privacy & security

Security built for project-critical workflows.

ScrubPlan protects project information while applying construction-specific AI responsibly. Your team stays in control of every output and every decision.

ScrubPlan trust centerHuman controlled
Protection principlesProject data stays protected
Responsible AI
Current public commitmentsStatus
Customer data is not used for model trainingInputs and outputs excluded by default
Protected
Encryption at rest and in transitIncluding traffic to service providers
Encrypted
Authorized access onlyLimited to documented business needs
Controlled

Four trust principles

Protect the information. Keep people in authority.

ScrubPlan combines data safeguards with a human-led approach to construction AI.

01

Your project data stays yours.

Customer inputs and outputs are not used to train or improve ScrubPlan models by default.

02

Protected in transit and at rest.

Sensitive data is encrypted while stored and while moving between customers, ScrubPlan, and service providers.

03

Access is controlled.

Access to customer data is limited to authorized employees who need it for engineering support, abuse prevention, or legal compliance.

04

Human authority remains final.

ScrubPlan surfaces risks and recommendations; construction professionals verify outputs and make final project decisions.

Responsible AI

AI augments construction expertise. It does not replace it.

ScrubPlan’s proprietary Intelligent Selection Model assigns identified materials and equipment to trades. Generative AI helps organize results into user-facing Scope Checklists and Auto SOW outputs.

Models are released incrementally, reviewed with human oversight, and improved through controlled feedback—not by training on customer account inputs or outputs.

Customer data

Clear boundaries around model development.

ScrubPlan states that customer data is not used to train or improve its models. Its published model-development approach uses publicly available knowledge, researcher-generated information, internal research and development, and trusted third-party partnerships.

Filters are applied to publicly available training content. Eligible customers can ask about data-residency options for regional requirements.

Security program

Controls across the information lifecycle.

The current public security inventory covers access, data protection, recovery, infrastructure, monitoring, organizational safeguards, vendor risk, and vulnerability management.

Access control

  • Formal access-granting process and least-privilege approach
  • Access-management and password policies
  • Regular employee-access reviews

Data protection

  • Encryption at rest and in transit
  • Data inventory and retention policies
  • Non-public cloud-storage controls

Disaster recovery

  • Automated backups for high-risk data and critical systems
  • Documented recovery and business-continuity processes
  • Recovery testing and isolated recovery data

Infrastructure security

  • Asset discovery and automated security scanning
  • Configuration management and infrastructure as code
  • Unique production-database authentication

Monitoring & response

  • Audit-log collection, storage, and management
  • Centralized log-management practices
  • Incident-response policy and incident-review process

Organizational security

  • Confidentiality, acceptable-use, and offboarding processes
  • Defined roles and documented development lifecycle
  • System-change communication and asset management

Risk & vendors

  • Risk-management policy and cybersecurity insurance
  • Vendor inventory and vendor-management program
  • Externally communicated security commitments

Vulnerability management

  • Automated patching practices
  • Vulnerability scanning
  • Documented vulnerability-management policy

This page summarizes ScrubPlan’s current public security statements and control inventory. It does not claim a certification. Contact sales for current scope, applicability, evidence, and enterprise review materials.

Planning an enterprise review?

Ask about security practices, data residency for eligible customers, identity options, permissions, and deployment planning.

Responsible AI for construction

Bring proactive intelligence into the workflow—securely.

Talk with the ScrubPlan team about your organization’s security, governance, and deployment requirements.