Skip to content

Security & trust

Security and privacy

Understand where your BIM data goes, how access is protected and what to review before an enterprise deployment.

Security / 01

Local model processing

Paramora Prism™ reads the active Navisworks model and writes the chosen output on your Windows workstation. Standard Export uses the live document. When entitled and explicitly enabled, Ultra Fast Export reads a clean, saved NWD through a separate local component. Neither conversion path uploads the source model to Neobuilt AB.

Your workstation

  1. 01

    Navisworks model

    Your source data

  2. 02

    Prism conversion

    Local processing

  3. 03

    Exported files

    Your chosen destination

Account and update requests are separate from model conversion. A cloud-synced folder, network drive or third-party plugin can introduce its own data transfers.

Your organisation controls workstation access, disk encryption, output permissions, backups and onward sharing. Treat exports, property sets, screenshots and diagnostics according to the model’s information classification.

Prism licensing and update documentation

Security / 02

Connected services and account protection

Local model processing still uses supporting online services. First installation enables delivery networking for account connection and component checks; you can change this in Settings. Disabling networking can affect activation, entitlement refresh and updates.

Account & licensing
Identity, organisation membership, licence and device activation records used to provide and protect access.
Software delivery
Version, platform, update and technical request data used to deliver the appropriate software components.
Billing & support
Purchase and billing records, correspondence and the diagnostic material you choose to provide.

Sign in through your browser

Prism opens the Neobuilt AB account site in your system browser. A one-time result returns through a local loopback callback. You do not enter your account password inside Navisworks, and the model is not part of this exchange.

Protect the local credential

Short-lived access material stays in memory. The refresh credential is protected for the current Windows user with Windows Data Protection API. Signed entitlement data controls the capabilities available to the local engine.

Restrict account access

Remote account connections use HTTPS. Secure sessions, server-side role checks and database access policies restrict access. Use the verification and second-factor options available in your account, and review device access when people or responsibilities change.

Keep support evidence focused

Start with a validation report, redacted diagnostics and reproduction steps. Share a model only when necessary, with the project owner’s permission and an agreed transfer method. Never include passwords, tokens or private keys.

Software data detailsSupport evidence checklist

Security / 03

Software distribution and updates

Download Prism from the official product page. Production installers use Windows Authenticode signing. An unsigned preview, when offered, is explicitly labelled with its publisher warning and SHA-256 checksum. A checksum alone does not authenticate a publisher.

Prism verifies the signed catalogue and component payloads before activation. A background catalogue check does not itself download or activate an update. A running export keeps one coherent component set until it finishes; connector changes can require Setup or a Navisworks restart.

Use Repair to re-verify active files. For managed deployments, agree release channels, rollout timing, offline arrangements and security-update support for the selected version. Do not copy engine or module files between workstations.

Components and repair reference

Security / 04

Personal data responsibilities

Neobuilt AB is established in Sweden. We act as controller for our own account, security, licensing and billing purposes. Processing on an organisation’s instructions is a separate role and needs the applicable data-processing agreement (DPA), scope and schedules. Local conversion alone does not send us your model for processing.

Request access, correction or erasure through the privacy contact at privacy@neo-built.com. Requests are assessed under applicable law; submitting an account deletion request does not immediately erase all records or cancel a subscription.

Security / 05

Standards and assurance

Enterprise assurance is specific to a product, service and deployment. These references help structure your assessment; they are not certification badges or a claim of compliance with every jurisdiction’s requirements.

GDPR & data protection

Personal data

Privacy responsibilities depend on the processing and each party’s role. Our privacy notice covers purposes, rights, retention and transfers. Organisation processing requires the applicable data-processing terms and completed schedules.

EU GDPR

ISO 19650-5

Sensitive built-asset information

This standard addresses security-minded information management for BIM and other asset information. Assess model sensitivity, limit disclosure and agree project access rules. Local processing can support your approach; using Prism does not establish conformity.

ISO 19650-5:2020

ISO/IEC 27001 & SOC 2

Independent assurance

No Neobuilt AB ISO/IEC 27001 certificate or SOC 2 report is published here. Provider certifications do not certify our products or operations. If independent assurance is a procurement requirement, confirm the available evidence and its scope before purchase.

ISO/IEC 27001:2022

Cyber Resilience Act

Software product obligations

For products in scope, EU reporting obligations apply from 11 September 2026 and the main requirements from 11 December 2027. Product classification, vulnerability handling, support periods and conformity evidence require a product-specific assessment. This page is not a declaration of conformity.

European Commission · CRA

NIS2 & regulated projects

Organisation & supply-chain risk

Applicability depends on the organisation, service, sector and national law. Customers may need supplier evidence even when a supplier is not directly in scope. Define your incident, continuity and information-handling requirements during procurement.

European Commission · NIS2

Open formats and security serve different purposes. IFC supports information exchange. A supported file format or a successful export does not certify information security, project compliance or the accuracy of downstream decisions.

Security / 06

Enterprise security review

Share your product and version, project sensitivity, intended countries, deployment model and required controls. We can then discuss the evidence and contractual terms needed for your review. Availability must be confirmed for your agreement.

Can Prism run offline or in a restricted environment?

Local conversion and offline licensing are separate. Ordinary account access uses online activation and a bounded entitlement grace period. Separately issued offline licences and signed offline media require an eligible agreement. Confirm the supported release, network dependencies and update route for your environment before deployment.

Read the offline licensing guidance
Is all service data kept in the EU?

The privacy notice identifies Stockholm as the primary account database region. That does not establish EU-only storage or access for every backup, log, payment or support service. Review the provider register and confirm actual locations and any required transfer safeguards for your agreement.

Review international transfers
Which enterprise controls should we confirm?

Ask about your exact identity-provider requirements, SAML or OIDC federation, SCIM provisioning, enforced MFA, audit-log export, deployment tooling and incident contacts. Availability is product- and agreement-specific; these are review topics, not features included by this page. Social sign-in alone does not establish enterprise federation or lifecycle management.

Discuss your required controls
What about availability, backups and security support?

Agree any uptime commitment, recovery time, recovery point, backup retention, tested restore evidence and security-update support period in writing for the relevant service and release. This page publishes no numerical SLA, recovery guarantee or fixed end-of-support date. Keep your own model and export backups under your organisation’s policies.

Review service terms and their status
Does this cover future BIM software or AI features?

The Prism statements describe the desktop workflows documented here. A future cloud, collaboration or AI feature needs its own data-flow description, processing purposes, providers, locations, retention and security terms before use. Confirm whether data is used for training, what human review is required and which AI rules apply. Prism’s local-processing boundary must not be assumed for another product.

European Commission · AI Act
Start an enterprise review Confirm requirements for your product and deployment.

Security / 07

Report a security concern

For a suspected vulnerability or account compromise involving Prism, a Neobuilt AB service or this website, contact our security team through the contact form. Include the product and version, affected URL or component, likely impact and safe reproduction steps. Use redacted evidence and ask for an appropriate transfer method before sharing sensitive material.

Report a security concern

We confirm receipt, investigate and coordinate disclosure with the reporter. Tell us how you would like to be credited. Test only systems and accounts you are authorised to assess; avoid accessing other people’s data or disrupting services. This policy does not authorise testing of third-party infrastructure.

Personal-data breach notification follows applicable law and the relevant agreement. For controller processing, GDPR notification to the supervisory authority is required without undue delay and, where feasible, within 72 hours of awareness, unless risk to individuals is unlikely. High-risk breaches generally also require notifying affected individuals without undue delay. Processor notification to the customer is a separate duty, required without undue delay under applicable law and the relevant agreement. It does not wait for a completed investigation.

Security advisories

Product advisories will identify affected versions, impact, available mitigations and a fixed version when available. Publication is coordinated to reduce risk and does not replace required notifications to customers or authorities. An absence of published advisories is not evidence that a product has no vulnerabilities.