A careful approach to data security and platform integrity
This page describes our current security approach using claims we can support from the platform and internal documentation. Roadmap items are identified separately from controls that are already in place.
Current Controls
Security claims we can support today
Access control
Authentication via Firebase Auth, role-based permissions, and row-level security in the database.
Platform integrity
Audit logging and project chronology patterns are used to support traceability across project activity.
Data protection
Encryption in transit, encryption at rest, and core data stored in Google Cloud London (`europe-west2`).
Operational access
No routine staff access to customer project data. Support access is only provided when authorised and is logged.
Threat Mitigation
Defence-in-depth where it matters most
Our security model is intended to combine identity, permissions, database enforcement, auditability, and infrastructure controls rather than relying on a single layer.
Examples
- Tenant isolation is enforced at the database layer with RLS.
- Files and BIM pipelines use validation controls including IFC header checks and zip-bomb protections.
- OAuth tokens for Autodesk integrations are documented as encrypted with AES-GCM.
- Signed URLs are used for cloud file access rather than direct bucket exposure from the browser.
Certification Alignment
Controls in place, certification work still in progress
We track our roadmap against the controls already present in the platform. Today, we can support claims around identity-based access control, row-level security, audit logging, encryption, signed URL file access, and documented AI security controls. Formal certification still depends on policy maturity, operational evidence, and external validation.
Cyber Essentials
Nearest certification target. Current work is focused on documentation, validation, and operational evidence.
SOC 2 Type II
Future target that depends on sustained control operation, policy maturity, and external audit readiness.
ISO 27001
Longer-term target that would require a formal information security management system and audit cycle.
Honest security communication matters
We would rather publish narrower, verifiable claims than overstate our posture. As controls mature, this page can expand with more detail and stronger external evidence.