Security

Security at ArchiPM-Nexus

Enterprise-grade security and compliance, built into every layer of the platform.

Last updated: August 15, 2026

SOC 2 Type II

Controls for security, availability, confidentiality and processing integrity — independently audited.

ISO 27001

Information security management system covering people, process and technology.

GDPR & Data Residency

EU-hosted data with clear residency, retention and subject-access controls.

SSO & RBAC

Single sign-on and role-based access control across every module and record.

Full Audit Trail

Every change to asset, work order and financial data is logged and traceable — audit-ready.

ISO 19650 (BIM Governance)

Validated, version-controlled BIM/IFC data from design handover through operations.

Infrastructure and hosting

The ArchiPM-Nexus platform is hosted on enterprise-grade cloud infrastructure located within the European Union. Our infrastructure providers are certified to industry standards and provide high availability, redundancy and disaster recovery capabilities.

Data encryption

All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using industry-standard algorithms. Encryption keys are managed through a dedicated key management service with restricted access.

Access control

Access to systems and data is governed by role-based access control (RBAC) and single sign-on (SSO). Access rights are granted on a least-privilege basis and reviewed regularly. All access to sensitive data is logged and monitored.

Application security

Our application development follows secure coding practices. We conduct regular code reviews, vulnerability scanning and penetration testing. Security patches are applied promptly following a risk-based assessment.

Incident response

We maintain a security incident response plan. In the event of a security incident, we follow a defined process to identify, contain, remediate and notify. Customers are notified of security incidents affecting their data without undue delay.

Business continuity

We maintain backup and disaster recovery procedures to ensure business continuity. Data backups are encrypted and stored in geographically separated locations. Recovery time and recovery point objectives are defined per service tier.

Compliance program

Our compliance program includes: - SOC 2 Type II — independently audited controls for security, availability, confidentiality and processing integrity - ISO 27001 — information security management system - GDPR — EU data protection compliance with EU data residency - ISO 19650 — validated, version-controlled BIM/IFC data governance Our compliance is regularly reviewed and independently assessed.

Security contact

To report a security vulnerability or for security-related questions, contact us at info@archipm.com. We acknowledge receipt within 48 hours and work with reporters to resolve valid issues.