BulletDraw

Resources · Trust

Security.

What protects your organization's data in BulletDraw, stated plainly: who can sign in, what each account can see, where documents live, and what gets recorded.

Scope of every query
1 org
Scope of every query
Screens under roles
55
Screens under roles
Verified webhooks
HMAC
Verified webhooks
Hosting and storage
AWS
Hosting and storage
Someone signing a document beside a laptop
Identity and access

Who can sign in, and what they can see.

Sign-in through Firebase Authentication

Accounts sign in with a verified email address or with Google. The server verifies the Firebase token on every request and resolves the user, the organization and the roles from it — never from the request itself.

Email verification · Google sign-in

Scoped to your organization

Every query is filtered by the organization of the signed-in user, and PostgreSQL row-level security enforces the same boundary underneath the application. One identity can belong to several organizations, each kept separate.

Application scoping + row-level security

Roles per screen and action

Admin, Builder, Project Manager and Viewer come as defaults and are fully editable. Permissions are set per screen and per action, the navigation hides what a role cannot use, and the server checks the same permission before acting.

4 default roles · 55 screens

Approvals with a named approver

Budgets, change orders, draws, payments, bids and purchase orders can require a sequential chain of named approvers, with send-backs that carry a reason.

Approval chains · send-backs

Outside your team

Lenders, subs and suppliers see only their part.

Lenders

A lender gets an account by emailed invite. What they can open is decided on the server by what was sent to them — the packages, and nothing else in your organization.

Decided server-side

Subcontractors and suppliers

A document request, a quote, a delivery confirmation, a handoff, an inspector checklist or a weekly report each arrives as a link that does one thing. No account is created for it.

Single-purpose links

Inbound webhooks

Signature completions from DocuSign and payment events from Moov are accepted only when their HMAC signature verifies. An unsigned or mismatched event is dropped.

HMAC-verified

Data and records

Where it lives, and what is recorded.

  • ✓Hosted on AWS. Documents — invoices, certificates, photos, packages — are stored in S3 and served through time-limited presigned links.
  • ✓Email is sent through AWS SES. AI workers run on SQS and Lambda against Anthropic Claude, and every result is confirmed by a person before it is used.
  • ✓An audit trail records who approved, what was sent back, and when the lender opened the package. A funded draw becomes a read-only record.
  • ✓The exceptions ledger records who accepted a compliance risk, why, and until when.
  • ✓Certifications: none to report today. Ask us and we will walk your team through the practices on this page.

Ask us anything about this.

We will walk your team through the practices above on a call, with the product open.

Works with any lender · Subs answer from a link