Trust Center

Security & Privacy at Blocks

Your Data. Protected by Design

At Blocks Platforms, safeguarding your data isn't just a feature — it's foundational. Security is at the core of everything we do, from how we build our platform to how we operate as a company.

We're equally committed to protecting your privacy. We understand that the data you entrust to us is not just valuable, it's personal, sensitive, and confidential. That's why we've designed our systems and processes with a strong focus on data protection and privacy.

Together, security and privacy form the foundation of our relationship with every customer.

Enterprise-Grade Security

We implement industry best practices security measures and frameworks to protect your business, including:

  • Data at rest is encrypted using AES 256
  • Data in transit across networks is encrypted using at minimum TLS 1.2
  • Passwords and tokens are encrypted
  • Firewall systems are in place to prevent unauthorized access
  • Continuous monitoring of systems and infrastructure for vulnerabilities and threats
  • Regular penetration testing and third-party security audits

Secure Development Lifecycle

Security is built into every stage of our R&D software development lifecycle:

01

Code reviews

Automated security scans on every change

02

Static & dynamic analysis

Continuous code-quality and vulnerability checks

03

Secure DevOps

DevSecOps practices wired into every release

Data Center

Our cloud-based service is hosted on Amazon Web Services infrastructure in Northern Virginia, across multiple Availability Zones, with a DR site established in a different region and with physical and environmental security measures — resulting in highly resilient infrastructure.

Compliance & Certifications

We're committed to meeting the highest standards of security and compliance: ISO/IEC 27001, SOC2 Type II and GDPR certified.

Learn more
GDPRSOC 2 Type IIISO 27001

Committed to your Privacy

Privacy by design

We view privacy not just as a legal obligation but as a core value. We are deeply committed to protecting the personal data of our users and customers, and we go to great lengths to design our platform and processes with privacy in mind from the ground up. Our platform is built for compliance with privacy regulations, including the GDPR, and we apply strict internal policies to govern how personal data is collected, stored, processed, and shared. Our systems are built to enable data minimization, purpose limitation, and transparency at every step, as we follow a "privacy by design" philosophy — ensuring that user data is collected, processed, and stored with care. Along with our comprehensive Privacy Policy, we support our customers' compliance needs with a Data Processing Addendum (DPA), outlining our commitments and practices regarding personal data handling.

Access to your Data

We understand that the data you share with our platform is private and confidential. That's why we've implemented internal controls aimed to ensure that your data is never accessed by anyone who shouldn't have access. By default, our team does not access the content you upload to our systems. A limited number of authorized personnel may have access to system-level data strictly for purposes such as ensuring platform stability, performance optimization, product improvement and security monitoring.

Secure & Private Use of AI Models

Our platform enables customers to build, integrate, and deploy AI/ML external models with speed and flexibility without compromising on security or privacy. All model-related operations are conducted within a secure environment, using encrypted channels and access-controlled infrastructure. We use AI models in standard, responsible ways, and we do not use customer data to train any model. Your data is never shared across tenants or exposed without your explicit consent. When leveraging third-party models or APIs, we ensure they meet our strict security and privacy standards. You data remains your intellectual property, and we are fully committed to ensuring that your use of AI within our platform remains secure, private, and compliant.

Your Security, Your Privacy, Our Responsibility

Whether you're a startup or an enterprise, we know your business depends on us. That's why we continuously invest in the security, reliability, and resilience of our platform so you can focus on growing your business, knowing your data is safe.

Have specific security questions or requirements? security@blocks.diy

Curious how we handle AI and your data? Read our AI Data & Security FAQs