SEC 04 — OUR STACK

This site runs on the exact stack we ship

Our Stack is the technology we build and host your site on — not a product you log into. Trust pages are easy to write and hard to prove, so here is the proof: boxbuild.agency runs on the same Cloudflare–Railway–Supabase architecture, the same no-plugin codebase, and the same security posture we deploy for every client. You are looking at the product.

The layers

APPLICATION LAYER

Next.js + Payload CMS

A custom, no-plugin application: React front end with a self-hosted headless CMS. No themes, no marketplace plugins, no supply-chain surprises.

EDGE & SECURITY

Cloudflare

DNS, WAF, TLS 1.3, bot management — every request filtered at the edge before it reaches the application.

COMPUTE + DATA

Railway

Isolated application and PostgreSQL per client. Private networking, no co-tenants, no shared hosting.

MEDIA

Supabase

Object storage for images and documents, encrypted at rest with AES-256.

SOURCE

GitHub

Every change version-controlled and reviewed before deploy. No FTP, no plugin updates in production.

MONITORING

UptimeRobot / BetterStack

Availability and Core Web Vitals watched continuously, with alerting to a human who can act.

OPTIONAL EDGE COMPUTE

Vercel

For engagements that need edge rendering or preview infrastructure, the same codebase deploys there without rework.

ENTERPRISE GRADE

The same providers and posture that back companies far larger than any agency.

FULLY MANAGED

We run it — updates, monitoring, security. You run your company.

YOU OWN IT

Your domain, your content, your data, your ad accounts. Always. Leaving is easy, which is why clients stay.

NO LOCK-IN

Standard technologies, exportable content, documented setup. No proprietary traps.

DWG E-01 — ONE-LINE DIAGRAM

The BoxBuild Stack

Edge security at Cloudflare. Isolated compute and PostgreSQL at Railway. Encrypted media at Supabase. Deployed from GitHub, with every change reviewed and versioned.

N.01 / EDGE

Cloudflare

DNS, WAF, SSL/TLS 1.3, bot management

N.02 / COMPUTE + DATA

Railway

Isolated app + PostgreSQL, private networking

N.03 / MEDIA

Supabase

Object storage, AES-256 encryption at rest

SOURCE — GITHUB · VERSION-CONTROLLED · REVIEWED DEPLOYS

No plugins, no shared hosting, no WordPress attack surface. Every provider in the chain holds SOC 2 attestations.

Enterprise security

Built to pass corporate security review — we answer enterprise CISO questionnaires with this platform.

MFA on all infrastructure accounts

Multi-factor authentication is enforced on every account that touches client infrastructure — hosting, DNS, source control, and CMS.

Least-privilege access

Role-based access with no shared logins. People get the minimum access their role requires, revoked when it ends.

Encrypted secrets

Credentials and API keys live as encrypted environment variables — never in source code, never in tickets.

WAF + DDoS mitigation

Cloudflare web application firewall with L3/4/7 DDoS mitigation in front of every deployment.

TLS 1.3 + HSTS in transit

All traffic encrypted in transit with modern TLS and HSTS enforced at the edge.

AES-256 at rest

Databases and media storage encrypted at rest with AES-256.

No third-party CMS plugins

No WordPress, no plugin supply chain, no theme vulnerabilities. Every line of code is version-controlled and reviewed.

Critical patches within 48 hours

Critical security patches are applied across the stack within 48 hours of release.

Daily encrypted backups

Automated daily encrypted backups with restoration procedures that are actually tested.

Audit logging with retention

Administrative and authentication events are logged and retained for review.

24-hour breach notification

If an incident affects your data, you hear it from us within 24 hours — with specifics.

Provider attestations

Railway, Supabase, Cloudflare, and GitHub maintain SOC 2 Type II / ISO 27001 attestations for the layers they operate.

BoxBuild builds on our providers’ attested controls; we don’t claim them as our own certification. The full security posture is documented for clients during onboarding.

Hosting & care tiers

Care

SCOPED ON THE CALL

For a site that needs to stay fast, secure, and up.

  • Infrastructure monitoring
  • Security updates
  • Backup management
  • Uptime monitoring
  • Platform stability monitoring
  • SSL & domain security management
Talk to us
MOST POPULAR

Care+

SCOPED ON THE CALL

For sites actively winning work, with a team that needs changes handled.

  • Everything in Care
  • Monthly platform health review
  • Minor content updates
  • Media updates
  • Performance monitoring
  • Priority technical support
  • Monthly support allowance
Talk to us
RECOMMENDED

Growth Care

SCOPED ON THE CALL

For firms treating the website as a revenue system.

  • Everything in Care+
  • Landing page adjustments
  • Conversion optimization improvements
  • Technical SEO fixes
  • Performance tuning
  • Analytics monitoring
  • Quarterly strategy call
  • Larger support allowance
Talk to us

ALWAYS-ON MONITORING

Uptime, performance, and security watched continuously — problems get caught before your prospects do.

FULLY MANAGED

No tickets into the void. We maintain the platform end to end so nothing lands on your team.

ONE ACCOUNTABLE PARTNER

Hosting, security, content, and performance under one roof — one call when anything needs attention.

Not sure which tier fits? We’ll recommend the right level of care based on your platform, traffic, and growth goals.

HOW WE WORK — FEEDBACK

Reviews happen on the page, not in email threads. Clients leave visual, in-page feedback via BugHerd — click the thing you want changed and comment on it directly. Nothing to install, no account needed.

Our Stack — questions we hear

Who owns the website, code, and content BoxBuild builds?

You own all of it — the code, the domain, the content, the data, and the ad accounts. Everything lives in standard technologies with a documented setup, so there is a clean handover path at any time. Leaving is deliberately easy, which is one reason clients stay. No proprietary traps, no held domains.

What technology stack does BoxBuild build construction websites on?

A custom, no-plugin application: a Next.js front end with the self-hosted Payload CMS, Cloudflare at the edge, the app and PostgreSQL database on Railway, media on Supabase, and all code version-controlled on GitHub. No WordPress, no marketplace plugins, no theme supply chain — the same enterprise-grade stack this site runs on.

Is a BoxBuild site secure enough to pass a corporate security review?

Yes — the platform is built to answer enterprise CISO questionnaires. MFA on every infrastructure account, a Cloudflare WAF with DDoS mitigation, TLS 1.3 in transit and AES-256 at rest, encrypted secrets, critical patching within 48 hours, daily encrypted backups, and audit logging. Railway, Supabase, Cloudflare, and GitHub hold SOC 2 / ISO 27001 attestations for the layers they operate.

What happens to our website if we stop working with BoxBuild?

You keep the asset. The code is in your GitHub, the site runs on infrastructure accounts you can audit, the content is exportable, and the domain is always yours. Because everything uses standard, portable technologies with documented setup, another team can take it over without a rebuild. There is no lock-in by design.

Who hosts and maintains a BoxBuild website after launch?

We do, end to end. Hosting, uptime and performance monitoring, security updates, and encrypted backups are fully managed under our care tiers, so nothing lands on your team. Monitoring is always-on, so problems get caught before your prospects see them, and one accountable partner covers hosting, security, content, and performance.

How fast are BoxBuild construction websites?

Fast by construction, not by patching. A no-plugin codebase on Cloudflare’s edge with continuous Core Web Vitals monitoring keeps pages quick and stable. Speed matters twice over: most buyers now judge you on a phone, and page experience is a ranking factor — so performance protects both the trust vet and your search visibility.

Browse the full FAQ

Kick the tires on our own infrastructure.

Run this site through Lighthouse. Check the headers. Read the llms.txt. Then let’s talk about yours.

Get in touch