Security & Data Governance Standards

Keep your data secure and compliant.

See how our best-in-class security program safeguards your data, manages risk, and helps you meet compliance standards—without compromising productivity.

Request A Demo

Compliance Certifications

AICPA Badge

SOC 1 (Type 2)

Report on Fairness—internal control over financial reporting.

AICPA-SOC2 Badge

SOC 2 (Type 2)

Trust Service Principles—security, availability, processing integrity, confidentiality, and privacy.

NIST logo

NIST 800-171

Safeguard and distribute information that is deemed sensitive.

ISO logo

ISO 27001:2013

Information Security Management System (ISMS) for any kind of digital information. 
Download certificate.

TRUSTED CLOUD INFRASTRUCTURE

Run your business on a secure, reliable cloud.

Trust in a global partner that supports you wherever you are, powered by a platform with world-class infrastructure, security, and privacy built into every layer.

  • Data encryption at rest and data in transit
  • Rely on 15+ secure global file storage locations
  • Stay up and running with 99.9% uptime for Procore's services
  • See detailed information about Procore's current system status
Check System Status
Illustration of mobile phone connecting to the cloud
ENTERPRISE-GRADE SECURITY

Control access to your information.

Take advantage of a robust set of security and data protection platform features that give you the tools you need to manage your security.

  • Secure authentication and password protection
  • Enable Single Sign-On (SSO) through secure tokens with SAML2 SSO and Security Assertion Markup Language (SAML) standard web browser protocols
  • Configure role-based permissions to control access to project data
Several construction workers gathered around a tablet
DATA PRIVACY & GOVERNANCE STANDARDS

Meet privacy standards and control project data.

Get the flexibility you need to control the contents of your Procore account(s) and extract data without custom code. Comply with global privacy standards including:  

  • California's Consumer Privacy Act (CCPA)
  • General Data Protection Regulation (GDPR)
  • Australia's Privacy Act of 1988
See Privacy Notice
Procore security badge illustration
AUTOMATED SECURITY PROTECTION

Multiple layers of defense.

To meet new challenges and demands, Procore continues to invest in broad initiatives that help ensure optimal security across our platform.

  • All Procore applications are scanned weekly for vulnerabilities and patched, including but not limited to, vulnerabilities identified in the Open Web Application Security Project Top 10
  • Procore employs countermeasures and technologies to prevent and dissuade attackers
  • Strict access control policies
  • Ongoing security training program to keep our teams current on the latest security innovations throughout the industry
Construction worker looking at iPad

Named #1 in JBKnowledge’s 2020 ConTech Report

Schedule a personal walkthrough to see how putting our customer's security first made us the leading construction management platform.

125+

Countries Served Worldwide

224+

Terabytes of Data Added Per Month in 2020

1M+

Trusted By 1M+ Jobsites

99.9%

Uptime

How does Procore store customer information?

For documents, photos, and attachments that users upload, Procore leverages Amazon Web Service's (AWS) highly secure data centers, S3 (Amazon Simple Storage Service). Amazon Web Services provides enterprise-class tools that have been proven to be both reliable and secure for today's web-based applications.

What encryption standard does Procore use to protect user data?

Procore employs many of the same data encryption standards, which are widely used by large online banking services. Data at rest is encrypted and stored behind Procore’s firewalls in a secure, private cloud infrastructure. 

How does the Transport Layer Security v1.2 requirement impact users?

Procore's network security architecture relies on the Transport Layer Security TLS v1.2 protocol for ensuring user interaction with Procore over the internet occurs securely without transmissions being vulnerable to outside entities. For data in transit, Procore encrypts data with 256-bit encryption. Data flowing between Procore and the user is encrypted with HTTPS protected by Transport Layer Security (TLS) 1.2. The primary benefit of TLS is the protection of web application data from unauthorized disclosure and modification when it is transmitted between clients (web browsers) and the web application server, and between the web application server and back end or other non-browser based enterprise components.

What is Procore's data backup strategy?

Procore maintains a robust “high-availability” strategy to protect our customers against software problems, hardware failure, and even large-scale natural disasters. Procore maintains several replicas of the application software on each server. All data are copied to off-site storage every 20 minutes. Replication distributes this offline snapshot across the United States. We maintain the software on dozens of servers and remote copies are maintained in different secure data centers. This diversity protects against hardware failure and local service issues.

How is security handled with third-party applications?

Procore employs what many consider the industry standard for API authentication - OAuth 2.0. The OAuth 2.0 authentication framework provides a secure means of authorizing and authenticating access to user data for third-party applications. OAuth 2.0 relies on SSL (Secure Sockets Layer) to ensure data transfer between the web server and browsers remains private and is kept safe. OAuth 2.0 protects Procore user data by providing access without revealing the identity of the user. Third-party applications make requests on behalf of the user without accessing passwords and other sensitive information.

Report a Security Vulnerability

If you believe Procore has a security vulnerability, please contact us right away. In your report, please include a description of the vulnerability and information to reproduce the vulnerability (including browser/OS versions, URLs, etc).

Contact Procore Security