It’s bid day. Your estimating files are locked, encrypted, and useless, and you didn’t even get breached directly. A vendor two or three steps removed from your business did. Now your bid window is closing and there’s nothing in it you can open.
That scenario is becoming more common, and it has nothing to do with how careful your team is. It has to do with how much of your business now runs through software you don’t control.
Contractors vet subcontractors and suppliers closely. Most don’t apply that same scrutiny to the software vendors holding their estimates, contracts, and financial data. That gap is exactly where risk is growing fastest.
The Stat That Should Get Your Attention
According to Verizon’s 2026 Data Breach Investigations Report, breaches involving third parties increased 60% year over year and now show up in 48% of all breaches – nearly half.
“Third party” doesn’t mean some distant, abstract risk. For most contractors, it means the everyday tools already in use: cloud-based takeoff and estimating platforms, project management software, accounting systems, and anything else holding sensitive project data.
The question isn’t only “will my business get breached?” It’s “will the software my business depends on get breached, and what happens to me if it does?”
What Vendor Risk Actually Looks Like on a Jobsite
Vendor risk isn’t one thing. It generally shows up in three ways:
- A flaw in your vendor’s product becomes your back door. A vulnerability in software you use gives an attacker a way into your systems, even though you did nothing wrong.
- Your data lives in someone else’s environment. If your vendor’s cloud environment is breached, your estimates, bids, and client information can be exposed right along with it, regardless of your own security practices.
- A vendor with access into your systems gets compromised. Integrations, remote support tools, and shared logins can all become a path from a vendor’s breach straight into your business.
None of these require your team to make a mistake. They require a vendor to make one.
Why This Matters More Now
Ransomware showed up in 48% of all breaches in this year’s report, and the real cost isn’t only stolen data. It’s downtime.
Attackers know that fewer victims are paying ransoms outright – 69% of ransomware victims declined to pay last year, up from 65% the year before. When payment gets less reliable, attackers lean harder into disruption instead, betting that a frozen business will feel more pressure to act than a threat of leaked data alone.
For a contractor, that disruption isn’t theoretical. It’s:
- Bid files locked during a submission window that won’t wait
- Draws stalled while accounting systems are down
- Payroll delayed in the middle of an active job
The fewer options a vendor’s breach leaves you, the more leverage an attacker has over your business even though you’re not who they targeted.
What to Look for in an Estimating Software Vendor
Vendor security doesn’t have to be a technical conversation. A few plain questions tell you most of what you need to know:
- Does the vendor require multifactor authentication (MFA), and is it enforced by default rather than optional?
- Does the vendor communicate clearly about how it handles a security incident, or does it go quiet?
- Does the vendor control its own third-party integrations and access permissions carefully?
- Does the vendor have a track record of transparency, not just a compliance logo on a webpage?
This is the same due diligence you already apply when bringing on a new sub or supplier. Estimating software deserves the same standard, because it holds more of your business than most vendors ever will.
STACK builds Takeoff & Estimate and Build & Operate around this standard, not as an afterthought but as part of what a platform holding your bids and project data should be expected to do.
How STACK Builds to This Standard
STACK doesn’t just talk about security. It’s independently verified.
STACK is SOC 2 compliant under the Security (Common Criteria) Trust Services Criteria, with independent auditors confirming STACK’s security controls meet industry standards. STACK also maintains its own availability and data protection practices, holds PCI DSS compliance for payment data, an A rating from SecurityScorecard, and an A+ rating from the Better Business Bureau.
On the questions that matter most for a contractor choosing software:
- Authentication: STACK supports single sign-on and two-factor authentication, so access to your project data is controlled, not just password-protected.
- Encryption: Data is encrypted in transit and at rest, whether it's sitting in the database or moving between your office and the field.
- Uptime and redundancy: STACK guarantees 99.9% uptime, backed by geographically separate data centers and automatic failover if one region goes down. Current uptime is public at status.stackct.com.
- Backups: Customer project data – bid pricing, materials, measurements, and annotations – is continuously backed up with point-in-time restore. Plan and drawing files stored separately currently use soft delete for recovery, with point-in-time restore for that storage layer in active development.
- Transparency: STACK's real-time security report is available for anyone to review at its Trust Center, rather than asking customers to take compliance claims on faith.
This is what “the same standard you’d hold a sub to” looks like in practice: independently audited, publicly verifiable, and built to keep your data available even on STACK’s worst day.
The Real Question to Ask Before You Choose Software
Picking an estimating platform used to come down to one question: does it save time on takeoff? That question still matters. But it’s no longer the only one.
The better question is this: if this vendor has its worst day, what happens to mine?
Getting the fundamentals right – in estimating and in the software you trust to hold your data – is what keeps a business standing when something goes wrong. That’s true on the jobsite, and it’s true in your tech stack.
FAQ
Third-party risk is the exposure a contractor takes on when a vendor they rely on – like an estimating, takeoff, or project management platform – experiences a security breach. Even if the contractor’s own systems are secure, a breach at the vendor level can expose their data, disrupt their operations, or both.
Verizon’s 2026 Data Breach Investigations Report found third-party involvement in breaches rose 60% year over year, reaching 48% of all breaches. Businesses of all sizes, including contractors, now rely on more cloud-based vendors than ever, which widens the number of paths an attacker can use to reach a company’s data.
If a vendor holding a contractor’s estimates, bids, or project data is hit with ransomware, the contractor can lose access to that data or face service outages, even though the attack targeted the vendor and not the contractor directly. This can delay bid submissions, draws, and payroll.
At minimum, contractors should look for enforced multifactor authentication (MFA), clear incident communication practices, careful management of third-party integrations, and a vendor with a transparent track record on security, not just marketing claims.
Cloud-based estimating software can be secure when the vendor follows strong practices around authentication, data handling, and incident response. The security of the platform depends more on the vendor’s practices than on the fact that it’s cloud-based.











