Family Type Manager BOMSync, Inc.

Security of your families & data

Family Type Manager runs on the same BOMSync, Inc. Microsoft Azure platform described on bomsync.com/security. Your Revit families (.rfa), Type Catalogs, Lookup Tables, and extract metadata are protected with encryption, company-scoped storage, and defense-in-depth network controls.

Microsoft Azure Encrypted everywhere Defense-in-depth Company-scoped storage Defender for Cloud Global compliance roadmap

Your Revit families stay under your organization

When you upload families in FTM, files and related family data are staged in Azure Blob Storage under a path scoped to your company — not a shared public folder. Other BOMSync customers cannot browse or download your .rfa files, Type Catalogs, Lookup CSVs, or parameter extract results.

  • Encrypted in transit — TLS between your browser, FTM, the BOMSync API, and Azure services.
  • Encrypted at rest — Azure Blob Storage applies AES-256 server-side encryption on every write.
  • Company isolation — family blobs live under your company prefix; entitlement and sign-in gate who can open My Families / Family Editor.
  • Time-limited access — when the platform issues file access, it uses short-lived Azure SAS permissions that expire automatically (no persistent account keys in the browser).
  • No ads, no data selling — BOMSync does not sell your family content or use it to train external models without your consent.

Account identity and billing sit in BOMSync’s platform services; your operational family files remain in the FTM Azure storage container with company-scoped paths. See also the data-ownership section on bomsync.com/security.

How we protect you

Commitments from the BOMSync Security & Trust page that apply directly to FTM.

Encrypted in transit and at rest, always

Every byte between your browser and BOMSync is protected by TLS. Stored data — including family files and related records — is encrypted at rest on Microsoft Azure. No exceptions.

Multiple layers of network protection

BOMSync runs inside Azure’s defense-in-depth framework: automatic DDoS protection, network-level firewall, and traffic isolation between service layers — so threats are stopped well before they reach your family data.

Your data never touches another customer’s

Each organization has its own dedicated, isolated BOMSync database for platform records. Family file storage is additionally partitioned by company so uploads do not commingle across customers.

Passwords and secrets are never stored as plain text

Passwords are hashed with a modern one-way algorithm. API keys and connection credentials are held in Azure Key Vault — a FIPS 140-3 certified hardware secrets store — and never embedded in client code.

Continuous threat monitoring

Microsoft Defender for Cloud and Azure Monitor watch BOMSync infrastructure around the clock, detecting suspicious activity and surfacing security alerts before they become incidents.

Automatic backups with point-in-time recovery

Azure Backup protects databases continuously. Where enabled, restores can target any point in the retention window — a safety net as well as a security posture.

Infrastructure

Built on Microsoft Azure — the same hosting layer described for BOMSync. These controls protect FTM family uploads and the platform services behind them.

Encrypted databases

Platform data at rest is protected by Azure SQL Transparent Data Encryption, with point-in-time restore enabled for every database.

Encrypted file storage

Revit families, catalogs, lookups, and related blobs use Azure Blob Storage with AES-256 server-side encryption on every write.

Hardware-backed secrets (FIPS 140-3)

Internal credentials live in Azure Key Vault, backed by HSMs certified to FIPS 140-3 Level 3 — never hard-coded in FTM or the API.

HSTS enforced

Browsers are instructed to refuse unencrypted connections to BOMSync properties. There is no HTTP fallback.

Azure Backup & point-in-time restore

Automated Azure backup protects databases so recovery can target any point within the retention window.

No ads. No data selling.

BOMSync is a professional B2B platform. We do not sell your data, share it with advertisers, or use it to train external models without your consent.

Azure Firewall & DDoS protection

Cloud-native firewall and automatic DDoS protection shield infrastructure from network-layer attacks without configuration on your part.

Network isolation

Azure Virtual Network boundaries and Network Security Groups keep services isolated and restrict traffic to what is explicitly permitted.

Defender for Cloud & Azure Monitor

Continuous monitoring for threats and misconfigurations, with audit logs and diagnostics for security analysis.

Microsoft Entra ID & least-privilege access

Identity and Azure RBAC ensure internal services can access only what they need — including managed identity for FTM blob operations.

Time-limited file access

File access uses short-lived, scoped Azure Shared Access Signature tokens that expire automatically.

Defense-in-depth by design

Independent controls at physical, network, compute, application, and data layers — so no single point of failure exposes your families.

The technologies and standards that protect your families

Family Type Manager runs on the BOMSync Azure platform. Every badge below is a control active in that production environment today, or a certification being pursued. Azure infrastructure certifications are Microsoft’s (hosting layer). Icons are inline SVG — no external trackers or CDN image requests.

Azure infrastructure

  • Microsoft Azure Cloud platform
  • Defense-in-depth 7-layer protection
  • FIPS 140-3 Level 3 HSM
    FIPS 140-3 L3 HSM-backed keys
  • Azure Key Vault Secrets management
  • Azure SQL TDE Encrypted at rest
  • Azure Blob Storage Secure file storage
  • Point-in-time restore Automated backup
  • Azure DDoS Platform protection

Identity & access management

  • Microsoft Entra ID Managed Identity
  • Azure RBAC Least-privilege access
  • PBKDF2 hashing Passwords protected

Encryption & transport security

  • TLS 1.2+ Encrypted in transit
  • HSTS enforced No HTTP fallback
  • AES 256-bit
    AES-256 Azure storage standard
  • End-to-end Every connection

Electronic signatures & legal compliance

  • eIDAS compliant EU Reg. 910/2014
  • US
    ESIGN Act US federal law
  • UETA compliant All 50 US states
  • UK
    UK ECA 2000 England & Wales
  • SHA 256
    SHA-256 Tamper-evident

Data privacy & industry standards

  • EU
    GDPR ready Data privacy
  • BIM
    ISO 19650 BIM information mgmt
  • PCI DSS Via Stripe
  • MCSB aligned MS cloud benchmark
  • No data selling Zero ad model

Azure infrastructure certifications (Microsoft’s — hosting layer)

  • ISO 27001 Azure infra
    ISO 27001 Azure infrastructure
  • SOC 2 Type II Azure infra
    SOC 2 Type II Azure infrastructure
  • CSA STAR
    CSA STAR Azure cloud security

These certifications are held by Microsoft for the Azure infrastructure layer. Under the cloud shared-responsibility model, BOMSync customers inherit infrastructure-level assurance. BOMSync application-level certifications are listed separately below.

BOMSync application certifications — in progress

  • SOC 2 Type II
    SOC 2 Type II In progress
  • ISO 27001
    ISO 27001 In progress
  • eIDAS QES
    eIDAS QES Roadmap
  • DFARS / FAR
    DFARS / FAR Roadmap

All icons are inline SVG — no external trackers. Azure infrastructure certifications (ISO 27001, SOC 2, CSA STAR) are held by Microsoft and apply to the hosting layer under the shared-responsibility model, not to BOMSync’s application code. BOMSync application-level SOC 2 and ISO 27001 are being pursued independently. “In progress” and “Roadmap” badges appear at reduced opacity.

Standards & roadmap

We are honest about what is live and what is coming. Architecture is designed to grow with AEC regulatory requirements — including government housing, infrastructure, and defense projects.

Live today

  • Dedicated encrypted database per organization
  • Defense-in-depth Azure security architecture
  • TLS 1.2+ with HSTS on all systems
  • Azure DDoS protection (auto-enabled)
  • Azure Firewall & network isolation (VNet / NSGs)
  • Microsoft Entra ID & least-privilege RBAC
  • FIPS 140-3 Level 3 hardware-backed secrets
  • AES-256 server-side encryption on all file storage
  • Company-scoped FTM family blob storage
  • Defender for Cloud continuous threat monitoring
  • Azure Monitor audit logging & diagnostics
  • Azure Backup with point-in-time restore
  • Hardware-backed secret management (Azure Key Vault)

On our roadmap

  • Qualified Electronic Signatures (eIDAS QES) for EU construction deliverables
  • Advanced signatures with trusted timestamps for US federal workflows
  • Long-term signature validation (PAdES B-LT / B-LTA)
  • Single Sign-On / SAML / OIDC federation for enterprise identity providers
  • SOC 2 Type II and ISO 27001 certifications (BOMSync application)
  • DFARS / FAR-compliant posture for US government contracts

Need the full platform detail?

Electronic signatures, legal compliance (eIDAS / ESIGN / UETA), and platform-wide diligence materials live on the main BOMSync Security & Trust page. That page is about BOMSync, Inc. platform security (the Azure environment FTM runs on) — not a service where FTM operators perform customer security audits.

Aligned with BOMSync Security & Trust (last reviewed on the public site 11 May 2026).

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.