Security

Private processing is the baseline.

Document tools handle sensitive material. Our architecture treats every upload as private, temporary and untrusted.

BuiltForAnything is operated by Awais in Victoria, Australia. These controls reduce risk but do not make uploads risk-free. BuiltForAnything has not been independently security-certified. Use it only where your organisation permits a third-party processor.

File lifecycle

Uploads travel over encrypted HTTPS into isolated processing jobs. Standard conversion jobs are scheduled to expire one hour after creation; longer-lived workflows display their selected expiry and permit earlier deletion or revocation.

  • No permanent document library by default
  • No document content used to train models
  • No public or guessable storage paths

Isolation and validation

Files are checked for size, extension and declared tool compatibility before processing. Conversion workers run with restricted resources, bounded execution time and network access limited to private state storage.

High-risk formats receive additional validation and isolated working directories.

Operational security

Secrets are stored outside source control, infrastructure access is restricted, and temporary storage uses scoped credentials. Application logs are designed to exclude document contents, filenames, passwords and capability tokens.

Report a concern

If you identify a security issue, email hello@builtforanything.com with the affected route and a safe reproduction. Do not attach confidential documents.