Trust
How we protect your work
LuminaBuilt holds estimates, contracts, pay applications, and project records. Your jobs stay with your company. We treat that as a non‑negotiable part of the product — not an afterthought.
Your company only
Every job, quantity list, and payment record belongs to your organization. People at other companies cannot see your work. Inside your firm, access follows the role you assign — estimator, project, coordinator, billing, or viewer.
Who can do what
Owners and admins manage the company. Project people run duties and awards. Estimators work quantities. Coordinators chase submittals and RFIs. Billing handles draws and holdback. Your plan decides which seats you can invite.
Sign-in
People sign in with email and password, or a one-time link sent to their inbox. Firm plans can use your company sign-in when you are ready for that setup.
Payments
Subscription cards are handled by our billing partner. LuminaBuilt never stores full card numbers on our side.
Quantities you can defend
Takeoff follows your drawings and schedules with a clear trail for each line. If evidence is missing, the system stops short of a firm number instead of guessing. You stay in charge of unit rates and the final bid.
Upload links for subs and suppliers
An upload link is a single, time-boxed invitation for one company. The link is stored only as a one-way hash, so nobody — including us — can recover it from the database; you see it once, when you create it. Uploads go to private storage, are limited by file type and size, and are visible only to your company. Expired, closed and unknown links all answer the same way, so a link can't be guessed at. You can close any link at once, and every document waits for someone in your office to accept it.
Document reading
When you read a drawing, specification, quote or contract, that document is sent to our model provider for that one request. It is not used to train models. We keep the result you choose to save plus usage metrics — item counts, timing and cost — not the document text. Every read is written to your company's audit trail, spending is capped per company per month, and an administrator can switch reading off; the rule-based reader keeps working either way.
How the service is hardened
Traffic is HTTPS only, with strict transport security, framing and content-type protections, and a content security policy. API responses are never cached by browsers or proxies, document reads are rate limited per company, and the drawing viewer is served from our own domain rather than a third-party network. Secrets stay on the server and never reach your browser.
Partners who help run the service
We use established providers for hosting, secure accounts, file storage, billing, and email notices. They process data only to operate LuminaBuilt for you. We do not sell your project information. Named subprocessors and processing terms are in our Data Processing Agreement.
Questions
Privacy or security concerns: support@luminabuilt.com