Security & compliance
Security you can trust.
Compliance you can count on.
Encryption in transit and at rest, granular access control, and an immutable audit trail behind every action.
Encryption
TLS 1.2+ in transit and AES-256 at rest across all project data and documents.
Access control
Role-based permissions down to register and document level, with SSO and SAML available.
Audit trail
Every upload, edit, approval, deletion and access event is recorded and cannot be altered.
Data residency
Hosting in the region you nominate, with UAE and wider GCC options for projects that require it.
Backup & recovery
Continuous backup with point-in-time recovery and a tested restore procedure.
Compliance
Controls aligned to ISO 27001, with documentation available for your own audit.
Common questions
Security FAQ
Access is role-based and scoped to project and register. External parties see only what is assigned to them. Every view and download is written to the audit log.
No. Audit records are append-only and cannot be altered or removed by any user, including administrators. This is what makes them usable as dispute evidence.
You can export every register, document and audit trail in open formats at any time during the contract and for an agreed period after it ends. Your data remains yours.
No. Project content is processed to generate insights and drafts for your team only, and is not used to train shared models or shared with other customers.
Need our security documentation?
We can share our controls documentation and answer your IT questionnaire.