Your building data,
protected and yours

Last Updated: July 30th 2026

Scope3D protects your building data with encryption,
access controls, and ownership you keep.

Encryption built in

Your files and twin stay encrypted in
transit and at rest — building data
stays protected.

Invitations and roles

Nobody joins your account on their
own. You invite people by email, and
a role decides what they can do.

You own it

The twin is yours, not ours —
your building data stays under your
control.

Export to IFC

The twin exports as open IFC — the
format Revit and other BIM tools
import. No lock-in.

Serious about
your data

We will not put a badge on this page for something we
have not earned. Two things we can state plainly:

Encrypted in transit and at rest Yours to export as IFC

What is actually
in place

No compliance language, no frameworks we are not audited
against. Just the six things that protect your building data.

Encrypted the whole way

Your drawings, your models and everything you write against them travel over TLS and sit encrypted at rest. That covers the upload, the twin and the documents attached to it.

Access is by invitation

There is no open sign-up into your account. You invite a person by email, they get a seat, and you can withdraw it the same way when the job ends.

A role, not a blanket login

Roles and seats are separate rights. Reading the twin, editing geometry and exporting the model are not the same permission, so a stakeholder who needs to look does not get the ability to change.

Scoped to the property

Buildings belong to your organisation, and access is granted against them. One property can be transferred or handed over on its own without opening the rest of the portfolio.

Isolation held in the database

Every row carries the organisation it belongs to and the database enforces that boundary itself. A mistake in the interface cannot hand you another account's building, because the interface is not what is holding the line.

Secrets kept out of the data

Connected services are stored as a reference, never as a copy of the key sitting next to your building records, and the endpoints that change anything run behind a server-side guard.

And what we do not have

A security page is only worth forwarding to your IT team if it lists the gaps as well. These are ours today.

No certification to show

No SOC 2 report, no ISO 27001 certificate, no published penetration test. When there is one, this page will name the auditor and the date rather than show you a logo.

No SSO and no two-factor

Sign-in is email and password, with invitations, roles and seats. If SAML single sign-on is a hard requirement for your organisation, say so before you buy, not after.

No public API

There are no endpoints to call and no keys to issue. Data comes in as files — IFC, Revit, DXF, PDF drawings, plan images, STEP — and leaves as IFC.

Confident because you
own it

Encryption, invitations and roles, and an IFC
export you can run yourself.

Own the twin of your building

Bring the files you already have. We will show you the twin you keep for the life of the building.

Book a demo View pricing