Third Party Index

Snapshot 27589

Document
Security page
URL
https://www.bluebeam.com/product/security/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
365930 bytes
SHA-256 (raw)
a949d44bc6ae8ee45822ea035500557416801abb99dcd4a02f3e29b47edbe7fd
SHA-256 (normalized text)
383c4035485c7ba7d6553eca1d557631abd91e4c4eed9f33f1168b8340be5d25

Normalized text

Scripts and page chrome removed; this is what change detection compares.

By Role
Architects
Engineers
General Contractors
Subcontractors
Estimators
Skilled Trades
MEP
By Industry Type
Energy
Public Sector
Infrastructure
Mining
Residential
Enterprise
By Workflow
Drawing Management
Design Review
Takeoffs
Site Logistics
RFIs
Submittals
Punch
Construction Closeout
Customer Stories
ZGF Architects
PDX Reimagined: How a Digital Backbone Powered America’s Most Ambitious Airport Project
Read More
View Our Plans Free Trial Download Bluebeam
See all solutions
Spotlight
Product Overview
What's New
Bluebeam Max
Core Capabilities
Markups
Collaboration
User Management
Security
AI & Innovation
Onboarding
Connected Workflows
Apps & Integrations
Integrations Directory
A new way to supercharge Revu with AI.
Explore Max
View Our Plans Free Trial Download Bluebeam
See it in Action
Learn
Learning Center
Bluebeam University
Training
Consulting
Certifications
Resources
Download Center
Technical Support
Webinars and Events
Resource Hub
Blog
Community
Community Forum
Community Overview
Academic Program
Customer Stories
The Complete Guide to Construction Takeoffs in 2026
Read More
View Our Plans Free Trial Download Bluebeam
Calculate your ROI with Bluebeam
Bluebeam Security Overview
Your data safety is our top priority.
Security starts with keeping your data where you expect it. Bluebeam runs locally by default and secures every cloud interaction — so you always know where your information is and how it’s protected.
Learn More
Learn More
How we protect your data
Most Revu features run locally, keeping your data on your network — it only leaves your environment when you actively choose to use a cloud-connected capability. And when you do, extensive security measures are in place to keep your data protected.
AWS Cloud Infrastructure
Bluebeam operations
Bluebeam application development
Cloud features run on AWS with additional Bluebeam-managed security controls layered on top.
Multi-AZ redundancy with daily backups
Continuous monitoring and GuardDuty threat detection
AES-256 encryption at rest, TLS in transit
Infrastructure-as-code — all changes auditable
Access to customer data is tightly controlled and monitored internally, with layered security controls across our environment.
MFA enforced across all internal systems
VPN and role-based access data control for employees
Log aggregation for threat detection and response
Endpoint security tooling on all employee devices
Security is built into every stage of product development.
Regular internal and third-party penetration testing
Automated vulnerability scanning at every build stage
Mandatory security training for all developers
Contractual breach notification SLAs
How we protect your data
Most Revu features run locally, keeping your data on your network — it only leaves your environment when you actively choose to use a cloud-connected capability. And when you do, extensive security measures are in place to keep your data protected.
AWS Cloud Infrastructure
Cloud features run on AWS with additional Bluebeam-managed security controls layered on top.
Multi-AZ redundancy with daily backups
Continuous monitoring and GuardDuty threat detection
AES-256 encryption at rest, TLS in transit
Infrastructure-as-code — all changes auditable
Bluebeam operations
Access to customer data is tightly controlled and monitored internally, with layered security controls across our environment.
MFA enforced across all internal systems
VPN and role-based access data control for employees
Log aggregation for threat detection and response
Endpoint security tooling on all employee devices
Bluebeam application development
Security is built into every stage of product development.
Regular internal and third-party penetration testing
Automated vulnerability scanning at every build stage
Mandatory security training for all developers
Contractual breach notification SLAs
Independently verified
SOC 2 Type II
Security & Availability Report available under NDA
ISO 27001
Annual external audit of our
security controls
EU GDPR Compliant
GDPR-aligned DPA + EU SCCs available
Data Privacy Framework
EU-approved framework for cross-border data protection extension certified
Cloud-connected capabilities
These features use cloud infrastructure. You can choose whether to allow your team to use them, or not.
Studio
Real-time collaboration with activity logs and revision control. Files sync to your chosen region.
Bluebeam on web
Browser-based access to your Bluebeam toolkit. Processed in your region’s cloud environment.
Bluebeam on mobile
Mark up files in the field. Changes sync to the cloud when connected.
AI features
Relevant content is processed by AI systems. Read more about how we use AI here.
Need to restrict cloud access?
Bluebeam offers options for organizations with stricter requirements.
Org Admin Pro (OAP)
OAP gives admins control over which cloud-connected capabilities (Studio, web, mobile, and AI) each user can access. It also grants Studio controls to block external collaborators, manage permissions, and manage projects/sessions. Learn more here.
Revu Offline
Revu Offline is a fully air-gapped offering with zero internet connectivity. The Revu markup, measurement, editing capabilities, with no external cloud exposure whatsoever.
Frequently asked questions
Where exactly does our data live?
All cloud-connected capabilities run on AWS. Users can select their data storage region: US, UK, AUS, DE, SE, or CA.
What happens to data if we delete a project?
Deleted Studio Sessions or Projects are retained for 120 days and can be restored upon request. After 120 days, they are permanently removed from Bluebeam’s servers.
What is the Bluebeam ID? Where does that data live?
Your Bluebeam ID is a centralized identity used to sign into Revu and verify your license, as well as access Bluebeam on web and mobile. The account record (email, credentials, license entitlement, and basic settings) is stored in a central authentication system. No project files or content are stored or transferred there.
Do you offer SSO/SCIM?
Yes. Single Sign-On (SSO) is supported across Revu and Bluebeam on web and mobile. It integrates with identity providers like Microsoft Entra ID and Okta, inheriting enterprise MFA and conditional access policies. A minimum of 10 seats is required for SSO configuration.
We have users restricted from accessing the internet. Can we still use Bluebeam?
Yes. Revu Offline is a fully air-gapped license with no internet connectivity or cloud exposure. All markup and measurement tools run entirely within your local environment.
How do we get the DPA or SCCs signed?
Contact your Bluebeam reseller or account team to request the Data Processing Addendum and EU Standard Contractual Clauses. A public sub-processor list is available on the Bluebeam DPA page.
Is there a live status page?
Yes. Visit status.bluebeam.com for real-time service availability and incident history. On the webpage, you can also sign up to receive status email notifications.
What happens in the event of a breach?
Bluebeam maintains a documented incident response program, with breach notification timelines defined in customer contracts as SLAs.
Discover what Bluebeam can do for you.
Learn More
Contact Sales