Security and privacy
Where your families are stored and who can reach them.
Work in progress
This page is a draft. Some sections are placeholders and details may change.
- Encrypted. Your files are encrypted in storage and in transit.
- Never on the open web. Private content is not publicly listed, and no stray link can expose your library.
- Private until you share. Access is controlled by your workspace roles and share settings. Families become publicly visible only when you publish them to the public gallery.
- Limited access. Access to stored data is restricted to authorized systems and personnel.
- Nothing gets lost. Every version is kept, so a bad overwrite can be undone. See Versions.
The full legal detail is in the policies.
Signing in
- Two-factor authentication. In General settings, Account, Security you can require a 6-digit code from an authenticator app every time you sign in.
- Your sessions. Account, Devices lists every browser or device that is signed in to your account, with its location details and when it was last active. To sign out one device, open its Session options menu (⋮) and choose the log-out option there. Use Log out of all devices if you see one you do not recognise, then change your password.
- Your password. Change it under Account, User preferences, or use Forgot your password? on the sign-in page.
When you delete something
- A family you delete goes to Trash and is removed for good after 30 days, or sooner if you choose Delete forever.
- Deleting an earlier version of a family removes it and its file permanently. See Versions.
- Delete account can be undone for 15 days; after that the account is erased.
TODO — More security topics
Add only what can be confirmed in the code or the policies page:
- Whether a Revit add-in sign-in is listed under Devices, and whether it can be signed out on its own. (B3)
- What happens to the files in a workspace when the account that owns it is deleted. (B3)