Security and privacy

Private by default.

BOM Compare is designed around a simple promise: BOMs, material exports, and supplier quotes should not need to leave the browser unless a customer explicitly chooses a future hosted workflow.

Current demo behavior

Built for sensitive project data.

Your BOMs, material exports, and supplier quotes can contain sensitive project scope, quantities, part numbers, pricing, and procurement context. This page describes the current browser-local product behavior; it is honest product guidance, not a final lawyer-reviewed SaaS privacy policy.

Files stay in your browser

The current demo reads and processes BOMs, material exports, and supplier quotes inside the browser session. Files do not need to leave the device for the core comparison workflow.

No raw file storage by default

The public demo does not create accounts, persist uploaded BOM / material list / supplier quote files, or store customer files on a server by default.

Customer-controlled exports

Users decide what to export: cleaned BOM CSV, revision-impact report CSV, quote-validation report CSV, formatted Excel report, or printable report preview.

Future cloud features must be explicit

If customer-controlled hosted file storage is added later, it needs clear controls and customer-facing data terms.

Enterprise conversations should stay honest.

Larger-company pilots should include security review support, clear data handling notes, and a crisp distinction between browser-local processing and any future customer-enabled hosted storage.

  • No SOC 2 claim until true
  • No ISO claim until true
  • No training on customer data
  • Private/offline workflow path planned

For IT and security teams

Everything your IT review will ask, answered up front.

What files can users compare?

BOMs, material lists, takeoff exports, buy lists, and supplier quote files.

Where are files processed?

In the user’s browser for the comparison workflow. Raw customer files do not need to transit our servers.

Are raw BOM or quote files stored?

Not by default. Account email, billing information if enabled, trial/workspace details, saved column mappings, usage counts, and settings may be stored when workspace features are used.

Are quote prices or part numbers sent to analytics?

No. Analytics should only track safe metadata like workflow type, file type, row count, summary counts, and duration.

Do you train AI on customer data?

No. BOM Compare does not train AI models on customer BOM or quote data.

What is your security certification status?

We do not claim SOC 2 or ISO certification today. We will publish those claims only after audits are complete.

How can IT review this?

Email and we’ll provide a security overview for review.

Need a private workflow review?

Use the 7-day Team trial to compare a real revision, then discuss whether browser-local, private deployment, or future customer-controlled storage fits your organization.

Discuss a private pilot