Bluebeam Security Overview

Your data safety is our top priority.

Security starts with keeping your data where you expect it. Bluebeam runs locally by default and secures every cloud interaction – so you always know where your information is and how it’s protected.

How we protect your data

Most Revu features run locally, keeping your data on your network – it only leaves your environment when you actively choose to use a cloud-connected capability. And when you do, extensive security measures are in place to keep your data protected.

  • AWS Cloud Infrastructure
  • Bluebeam operations
  • Bluebeam application development

Cloud features run on AWS with additional Bluebeam-managed security controls layered on top.

  • Multi-AZ redundancy with daily backups
  • Continuous monitoring and GuardDuty threat detection
  • AES-256 encryption at rest, TLS in transit
  • Infrastructure-as-code – all changes auditable

Access to customer data is tightly controlled and monitored internally, with layered security controls across our environment.

  • MFA enforced across all internal systems
  • VPN and role-based access data control for employees
  • Log aggregation for threat detection and response
  • Endpoint security tooling on all employee devices

Security is built into every stage of product development.

  • Regular internal and third-party penetration testing
  • Automated vulnerability scanning at every build stage
  • Mandatory security training for all developers
  • Contractual breach notification SLAs

How we protect your data

Most Revu features run locally, keeping your data on your network – it only leaves your environment when you actively choose to use a cloud-connected capability. And when you do, extensive security measures are in place to keep your data protected.

  • AWS Cloud Infrastructure

    Cloud features run on AWS with additional Bluebeam-managed security controls layered on top.

    • Multi-AZ redundancy with daily backups
    • Continuous monitoring and GuardDuty threat detection
    • AES-256 encryption at rest, TLS in transit
    • Infrastructure-as-code – all changes auditable
  • Bluebeam operations

    Access to customer data is tightly controlled and monitored internally, with layered security controls across our environment.

    • MFA enforced across all internal systems
    • VPN and role-based access data control for employees
    • Log aggregation for threat detection and response
    • Endpoint security tooling on all employee devices
  • Bluebeam application development

    Security is built into every stage of product development.

    • Regular internal and third-party penetration testing
    • Automated vulnerability scanning at every build stage
    • Mandatory security training for all developers
    • Contractual breach notification SLAs

Independently verified

SOC 2 Type II

Security & Availability Report available under NDA

ISO 27001

Annual external audit of our
security controls

EU GDPR Compliant

GDPR-aligned DPA + EU SCCs available

Data Privacy Framework

EU-approved framework for cross-border data protection extension certified

Cloud-connected capabilities

These features use cloud infrastructure. You can choose whether to allow your team to use them, or not.

Studio

Real-time collaboration with activity logs and revision control. Files sync to your chosen region.

Bluebeam on web

Browser-based access to your Bluebeam toolkit. Processed in your region’s cloud environment.

Bluebeam on mobile

Mark up files in the field. Changes sync to the cloud when connected.

AI features

Relevant content is processed by AI systems. Read more about how we use AI here.

Need to restrict cloud access?

Bluebeam offers options for organisations with stricter requirements.

Org Admin Pro (OAP)

OAP gives admins control over which cloud-connected capabilities (Studio, web, mobile and AI) each user can access. It also grants Studio controls to block external collaborators, manage permissions and manage projects/sessions. Learn more here.

Revu Offline

Revu Offline is a fully air-gapped offering with zero internet connectivity. The Revu markup, measurement, editing capabilities, with no external cloud exposure whatsoever.

Frequently Asked Questions

Where exactly does our data live?

What happens to data if we delete a project?

What is the Bluebeam ID? Where does that data live?

Do you offer SSO/SCIM?

We have users restricted from accessing the internet. Can we still use Bluebeam?

How do we get the DPA or SCCs signed?

Is there a live status page?

What happens in the event of a breach?

Discover what Bluebeam can do for you.