Protected sign-in
Firebase Authentication identities are paired with signed, HTTP-only application sessions and verified-email onboarding.
Security at ProBuilder OS
ProBuilder OS protects internal company work, client information, and role-specific access while preserving the activity history owners need to operate responsibly.
Control summary reviewed August 12, 2026.
Firebase Authentication identities are paired with signed, HTTP-only application sessions and verified-email onboarding.
Owner, admin, sales, project, field, and client responsibilities are checked in both interface and server-side workflows.
Internal application routes require a valid session and are explicitly marked no-index for search engines.
Important form input is validated before a server-side mutation, and key operating actions leave an activity record.
A complete issued proposal is frozen and hash-bound to a verified client. Recent authentication, versioned consent, idempotent acceptance, and a protected signed receipt preserve the exact accepted record.
AI scope drafting sends a redacted contractor brief and selected project characteristics without provider application storage. Generated drafts and usage provenance remain protected inside the company workspace for review and plan enforcement.
Launch-stage boundary
ProBuilder OS is available as a launch-stage service and does not currently claim third-party compliance certifications. Company data is stored in Firebase-backed, tenant-scoped records and files, with server authorization and Firebase Security Rules protecting supported access paths. Formal compliance, enterprise backup commitments, and regulated-data agreements are not included unless stated in writing.
Send a clear description and reproduction steps to info@terrabuildr.com. Do not access, alter, or retain data that is not yours.