Resources · Trust
Security.
What protects your organization's data in BulletDraw, stated plainly: who can sign in, what each account can see, where documents live, and what gets recorded.
- Scope of every query
- 1 org
- Scope of every query
- Screens under roles
- 55
- Screens under roles
- Verified webhooks
- HMAC
- Verified webhooks
- Hosting and storage
- AWS
- Hosting and storage

Who can sign in, and what they can see.
Sign-in through Firebase Authentication
Accounts sign in with a verified email address or with Google. The server verifies the Firebase token on every request and resolves the user, the organization and the roles from it — never from the request itself.
Email verification · Google sign-in
Scoped to your organization
Every query is filtered by the organization of the signed-in user, and PostgreSQL row-level security enforces the same boundary underneath the application. One identity can belong to several organizations, each kept separate.
Application scoping + row-level security
Roles per screen and action
Admin, Builder, Project Manager and Viewer come as defaults and are fully editable. Permissions are set per screen and per action, the navigation hides what a role cannot use, and the server checks the same permission before acting.
4 default roles · 55 screens
Approvals with a named approver
Budgets, change orders, draws, payments, bids and purchase orders can require a sequential chain of named approvers, with send-backs that carry a reason.
Approval chains · send-backs
Lenders, subs and suppliers see only their part.
Lenders
A lender gets an account by emailed invite. What they can open is decided on the server by what was sent to them — the packages, and nothing else in your organization.
Decided server-side
Subcontractors and suppliers
A document request, a quote, a delivery confirmation, a handoff, an inspector checklist or a weekly report each arrives as a link that does one thing. No account is created for it.
Single-purpose links
Inbound webhooks
Signature completions from DocuSign and payment events from Moov are accepted only when their HMAC signature verifies. An unsigned or mismatched event is dropped.
HMAC-verified
Where it lives, and what is recorded.
- ✓Hosted on AWS. Documents — invoices, certificates, photos, packages — are stored in S3 and served through time-limited presigned links.
- ✓Email is sent through AWS SES. AI workers run on SQS and Lambda against Anthropic Claude, and every result is confirmed by a person before it is used.
- ✓An audit trail records who approved, what was sent back, and when the lender opened the package. A funded draw becomes a read-only record.
- ✓The exceptions ledger records who accepted a compliance risk, why, and until when.
- ✓Certifications: none to report today. Ask us and we will walk your team through the practices on this page.
Ask us anything about this.
We will walk your team through the practices above on a call, with the product open.
Works with any lender · Subs answer from a link