cbcivil.buildersA5DOpen A5D

LEGAL · VERSION 2026.07.23-r2

Security and Retention Statement

1. Baseline controls

A5D uses server-verified identity, server-side tenant/project/role checks, required country declarations, invitation and billing-country checks, TLS and provider encryption at rest, secrets outside source, signed idempotent payment webhooks, paid-only scoped AI, review and test gates, least privilege, rate limits, protected logs and customer permission/export controls. A protected country-level infrastructure signal may supplement these controls when already available, but A5D does not claim comprehensive geolocation. This is not a certification or guarantee.

2. Incident handling

A5D identifies, contains, investigates, preserves appropriate evidence, remediates and provides legally required notices. Send security reports privately to support@civil.builders without accessing unrelated data.

3. Retention enforcement

Workspace closure makes project content read-only for export. Verified deletion requests are processed through the application and support workflow; provider recovery backups currently retain data for seven days. Security, audit, consent, billing and support records may remain where required for security, accounting, disputes or law. Optional user analytics is limited to 14 months where configurable. Documented legal holds restrict ordinary use and deletion.

4. Shared responsibility and no certification

Customers protect credentials and endpoints, use appropriate roles, remove former users, minimise sensitive data, retain independent records and review audit events. A5D does not claim ISO, SOC, PCI, GDPR or other certification merely because a provider holds one.