Legal

Data security

Last updated: 15 September 2026

Construction drawings are commercially sensitive. This page sets out, in plain terms, how AEC NEXT protects the files and information you entrust to us.

Encryption

All traffic between your browser and our platform is encrypted using TLS. Files and derived data are encrypted at rest using industry-standard algorithms. Credentials are stored using one-way hashing and are never retrievable in plain text.

How uploaded drawings are handled

  • Files are received over an encrypted connection and placed in isolated, access-controlled storage.
  • Processing is scoped to your account. Files from different customers are never combined.
  • Once your report is generated and delivered, source files are cleared from processing systems within the retention window applicable to your plan.
  • Drawings are not used to train machine-learning models, and are not shared with or made visible to other customers.

Access control

Access to production systems is limited to named personnel who need it to operate the Service, protected by multi-factor authentication and reviewed periodically. Customer accounts support seat-based access, and role controls are available on Enterprise plans. Administrative actions are logged.

Infrastructure

The platform runs on established cloud infrastructure with managed physical security, redundancy and patching. Environments for development, testing and production are kept separate. Backups are encrypted and restoration is tested periodically.

Sub-processors

We use a small number of third-party providers for hosting, AI inference, payment processing and support tooling. Each is bound by contractual confidentiality and data-protection obligations. A current list is available to customers on request.

Monitoring and incident response

Systems are monitored for anomalous activity and availability. We maintain an incident response process covering identification, containment, remediation and review. Where an incident affects your data, we will notify you without undue delay along with the facts known at that point and the steps being taken.

Business continuity

Data is backed up regularly and recovery procedures are documented so that service can be restored following a significant failure.

Your responsibilities

  • Keep credentials confidential and enable multi-factor authentication where offered.
  • Remove seats promptly when a team member leaves.
  • Upload only material you are entitled to share with a processing service.

Responsible disclosure

If you believe you have found a security vulnerability, please write to hello@aecnextgen.com with enough detail to reproduce it. We ask that you allow us a reasonable period to remediate before any public disclosure, and we will not pursue action against good-faith research conducted without harm to customer data.

Certifications

Formal certification is on our roadmap as the platform matures. Enterprise customers can request our current security documentation and a security questionnaire response during procurement.

Contact

Questions about this document can be sent to hello@aecnextgen.com or by post to:

AEC Next Private Limited
823, Dev Atelier, 100 Feet Road,
Prahlad Nagar, Ahmedabad
Gujarat, India
+91 96994 66900