Your Revit families stay under your organization
When you upload families in FTM, files and related family data are staged in Azure Blob Storage under a
path scoped to your company — not a shared public folder. Other BOMSync customers cannot browse or download
your .rfa files, Type Catalogs, Lookup CSVs, or parameter extract results.
- Encrypted in transit — TLS between your browser, FTM, the BOMSync API, and Azure services.
- Encrypted at rest — Azure Blob Storage applies AES-256 server-side encryption on every write.
- Company isolation — family blobs live under your company prefix; entitlement and sign-in gate who can open My Families / Family Editor.
- Time-limited access — when the platform issues file access, it uses short-lived Azure SAS permissions that expire automatically (no persistent account keys in the browser).
- No ads, no data selling — BOMSync does not sell your family content or use it to train external models without your consent.
How we protect you
Commitments from the BOMSync Security & Trust page that apply directly to FTM.
Encrypted in transit and at rest, always
Every byte between your browser and BOMSync is protected by TLS. Stored data — including family files and related records — is encrypted at rest on Microsoft Azure. No exceptions.
Multiple layers of network protection
BOMSync runs inside Azure’s defense-in-depth framework: automatic DDoS protection, network-level firewall, and traffic isolation between service layers — so threats are stopped well before they reach your family data.
Your data never touches another customer’s
Each organization has its own dedicated, isolated BOMSync database for platform records. Family file storage is additionally partitioned by company so uploads do not commingle across customers.
Passwords and secrets are never stored as plain text
Passwords are hashed with a modern one-way algorithm. API keys and connection credentials are held in Azure Key Vault — a FIPS 140-3 certified hardware secrets store — and never embedded in client code.
Continuous threat monitoring
Microsoft Defender for Cloud and Azure Monitor watch BOMSync infrastructure around the clock, detecting suspicious activity and surfacing security alerts before they become incidents.
Automatic backups with point-in-time recovery
Azure Backup protects databases continuously. Where enabled, restores can target any point in the retention window — a safety net as well as a security posture.
Infrastructure
Built on Microsoft Azure — the same hosting layer described for BOMSync. These controls protect FTM family uploads and the platform services behind them.
Encrypted databases
Platform data at rest is protected by Azure SQL Transparent Data Encryption, with point-in-time restore enabled for every database.
Encrypted file storage
Revit families, catalogs, lookups, and related blobs use Azure Blob Storage with AES-256 server-side encryption on every write.
Hardware-backed secrets (FIPS 140-3)
Internal credentials live in Azure Key Vault, backed by HSMs certified to FIPS 140-3 Level 3 — never hard-coded in FTM or the API.
HSTS enforced
Browsers are instructed to refuse unencrypted connections to BOMSync properties. There is no HTTP fallback.
Azure Backup & point-in-time restore
Automated Azure backup protects databases so recovery can target any point within the retention window.
No ads. No data selling.
BOMSync is a professional B2B platform. We do not sell your data, share it with advertisers, or use it to train external models without your consent.
Azure Firewall & DDoS protection
Cloud-native firewall and automatic DDoS protection shield infrastructure from network-layer attacks without configuration on your part.
Network isolation
Azure Virtual Network boundaries and Network Security Groups keep services isolated and restrict traffic to what is explicitly permitted.
Defender for Cloud & Azure Monitor
Continuous monitoring for threats and misconfigurations, with audit logs and diagnostics for security analysis.
Microsoft Entra ID & least-privilege access
Identity and Azure RBAC ensure internal services can access only what they need — including managed identity for FTM blob operations.
Time-limited file access
File access uses short-lived, scoped Azure Shared Access Signature tokens that expire automatically.
Defense-in-depth by design
Independent controls at physical, network, compute, application, and data layers — so no single point of failure exposes your families.
Standards & certifications
The technologies and standards that protect your families
Family Type Manager runs on the BOMSync Azure platform. Every badge below is a control active in that production environment today, or a certification being pursued. Azure infrastructure certifications are Microsoft’s (hosting layer). Icons are inline SVG — no external trackers or CDN image requests.
Azure infrastructure
- Microsoft Azure Cloud platform
- Defense-in-depth 7-layer protection
- FIPS 140-3 L3 HSM-backed keys
- Azure Key Vault Secrets management
- Azure SQL TDE Encrypted at rest
- Azure Blob Storage Secure file storage
- Point-in-time restore Automated backup
- Azure DDoS Platform protection
Identity & access management
- Microsoft Entra ID Managed Identity
- Azure RBAC Least-privilege access
- PBKDF2 hashing Passwords protected
Encryption & transport security
- TLS 1.2+ Encrypted in transit
- HSTS enforced No HTTP fallback
- AES-256 Azure storage standard
- End-to-end Every connection
Electronic signatures & legal compliance
- eIDAS compliant EU Reg. 910/2014
- ESIGN Act US federal law
- UETA compliant All 50 US states
- UK ECA 2000 England & Wales
- SHA-256 Tamper-evident
Data privacy & industry standards
- GDPR ready Data privacy
- ISO 19650 BIM information mgmt
- PCI DSS Via Stripe
- MCSB aligned MS cloud benchmark
- No data selling Zero ad model
Azure infrastructure certifications (Microsoft’s — hosting layer)
- ISO 27001 Azure infrastructure
- SOC 2 Type II Azure infrastructure
- CSA STAR Azure cloud security
These certifications are held by Microsoft for the Azure infrastructure layer. Under the cloud shared-responsibility model, BOMSync customers inherit infrastructure-level assurance. BOMSync application-level certifications are listed separately below.
BOMSync application certifications — in progress
- SOC 2 Type II In progress
- ISO 27001 In progress
- eIDAS QES Roadmap
- DFARS / FAR Roadmap
All icons are inline SVG — no external trackers. Azure infrastructure certifications (ISO 27001, SOC 2, CSA STAR) are held by Microsoft and apply to the hosting layer under the shared-responsibility model, not to BOMSync’s application code. BOMSync application-level SOC 2 and ISO 27001 are being pursued independently. “In progress” and “Roadmap” badges appear at reduced opacity.
Standards & roadmap
We are honest about what is live and what is coming. Architecture is designed to grow with AEC regulatory requirements — including government housing, infrastructure, and defense projects.
Live today
- Dedicated encrypted database per organization
- Defense-in-depth Azure security architecture
- TLS 1.2+ with HSTS on all systems
- Azure DDoS protection (auto-enabled)
- Azure Firewall & network isolation (VNet / NSGs)
- Microsoft Entra ID & least-privilege RBAC
- FIPS 140-3 Level 3 hardware-backed secrets
- AES-256 server-side encryption on all file storage
- Company-scoped FTM family blob storage
- Defender for Cloud continuous threat monitoring
- Azure Monitor audit logging & diagnostics
- Azure Backup with point-in-time restore
- Hardware-backed secret management (Azure Key Vault)
On our roadmap
- Qualified Electronic Signatures (eIDAS QES) for EU construction deliverables
- Advanced signatures with trusted timestamps for US federal workflows
- Long-term signature validation (PAdES B-LT / B-LTA)
- Single Sign-On / SAML / OIDC federation for enterprise identity providers
- SOC 2 Type II and ISO 27001 certifications (BOMSync application)
- DFARS / FAR-compliant posture for US government contracts
Need the full platform detail?
Electronic signatures, legal compliance (eIDAS / ESIGN / UETA), and platform-wide diligence materials live on the main BOMSync Security & Trust page. That page is about BOMSync, Inc. platform security (the Azure environment FTM runs on) — not a service where FTM operators perform customer security audits.