Get the beta

Builds · Legal

Security

How Builds is built to keep your work safe

Your credentials stay on your machine. You sign in to Claude, ChatGPT/Codex or Grok on the machine itself, with the vendor's own tool. API keys are stored on that machine, encrypted at rest (AES-256-GCM). A key you type in the app is sealed on your phone to that one machine (X25519 and AES-256-GCM) before it leaves; our server passes on only the sealed envelope, which it cannot open. app.builds.one never holds a usable key, so a breach of our server cannot leak them.

Your conversations stay on your machine. app.builds.one relays them to your devices and does not write them to disk.

What our server does hold, it holds carefully.

  • Device sign-in tokens and machine credentials are stored only as hashes.
  • The few secrets it must keep (a linked DispatChai sign-in, a FrontierScore key, an invitation link for its sender) are encrypted with a key kept apart from the data.
  • Its data is backed up daily, encrypted, and a restore is rehearsed.

Access.

  • A machine joins your account only with a one-time code you get in the app. Wrong codes are limited: 5 wrong in 15 minutes locks the network address, and a flood of wrong codes closes pairing for everyone for a while.
  • Risky actions (making a desk, removing a machine, adding or removing an API key, sending an invitation, changing a team's key or members, rewinding a conversation) ask for Face ID on iPhone and iPad, or a second press on the web and Android. Our server refuses them without it.
  • You can see every app signed in to your account in Settings, and sign any of them out.

The web. app.builds.one is served only over HTTPS (HSTS, one year), with a strict Content Security Policy (our own scripts and styles only, no third-party code, no framing).

Teams. On an organisation's machine each member's space is a separate operating-system user, so one member's agent cannot read another's files or credentials. The machine's own administrator can read everything on it, and the app says so before a member makes a space.

Updates. Builds updates itself from app.builds.one, and each install checks the release's signature and checksum before installing it.

What we do not claim

  • Our server is part of your machine's security. A linked machine does what comes to it over its link from your account: start a turn, answer a question, make a desk. So whoever controls app.builds.one could, technically, send your machine such a command. We protect the server for that reason and we use that path only to carry your own actions. The machine takes only Builds' own commands (the ones the app's buttons send), but an agent's turn can do whatever you allowed the agent to do there. If that is not acceptable for a machine, unlink it (builds residence unlink) and use Builds there from the terminal only.
  • We hold no ISO 27001 or SOC 2 certificate, and no independent penetration test has been done so far.
  • We cannot protect a machine you run: keep it patched, and be careful which permission mode you give an agent (an agent in "auto" or "bypass" runs commands without asking you).
  • No system is perfectly secure. If a breach puts your rights at risk, we tell Ireland's Data Protection Commission within 72 hours and you without undue delay where the risk to you is high.

Reporting a vulnerability

If you think you found a security problem in builds.one, app.builds.one, the Builds apps or the builds software, please tell us.

  • Email: info@digital1.one, with "Security" in the subject.
  • Tell us what you found, how to reproduce it, and what it could let someone do. Screenshots or a short proof of concept help.

What we do:

  • confirm we got it within 3 working days;
  • tell you what we think and what we will do within 10 working days;
  • fix it as fast as its risk needs, and tell you when it is fixed;
  • credit you, if you want, once it is fixed.

What we ask:

  • Give us reasonable time to fix it before you tell anyone else (90 days, or sooner by agreement).
  • Test only against your own account and your own machines. Do not read, change or delete other people's data; if you reach some by accident, stop, and tell us.
  • No denial-of-service, no spam, no social engineering of our people, and no physical attacks.
  • Do not test DispatChai's, Hostinger's, Cloudflare's or PostHog's own systems through us.

Safe harbour. If you act in good faith within these rules, we will not take legal action against you for your research, and we will say so to anyone who asks.

Out of scope: reports from automated scanners with no shown impact, missing headers with no shown impact, and the AI vendors' own services (report those to the vendor).

For the record

Builds is software placed on the EU market by Digital One Technology Consulting Limited. Where the EU Cyber Resilience Act applies to it, actively exploited vulnerabilities and severe incidents are reported to ENISA's single reporting platform within 24 hours of our becoming aware (Regulation (EU) 2024/2847, Art. 14, applying since 11 September 2026).

Last updated