Skip to security content

Security and trust

Security & Trust

Security controls built into the operating model, with clear boundaries for company work, customer access and protected drawings.

The operating model

Clear boundaries for the work you share.

Understand the product controls first. Review published evidence and its scope before making procurement or compliance decisions.

Access follows the company, role and assignment.

Contractor record access is checked on the server against company membership and role. Project managers work within assigned projects; technicians work within their field assignments.

Financial administration is separated from project coordination and field execution.

Customer access is a separate experience.

Customer accounts use a separate sign-in and see supported records explicitly published to them. Internal contractor notes and workspace controls do not become customer-visible simply because a customer account exists.

Customer decisions use controlled approval links. Customer messages remain in contractor-started conversations.

Drawing access is checked before a file opens.

Protected drawing requests are checked for authorization and file security state before delivery. File access also follows publication, scan and lifecycle rules.

Files awaiting security review or blocked by lifecycle policy are not made available through the protected file workflow. Processing availability and supported file types still matter.

Account and request controls support everyday work.

Password and session controls include session invalidation and checks against recent password reuse. Application request checks and workflow rate limits help restrict unauthorized or repeated requests.

These controls support the operating model; they are not a certification or a guarantee that every security risk is eliminated.

Diagnostics are handled with disclosure limits.

Diagnostic reporting applies sanitization before sending supported events to configured monitoring. Monitoring delivery depends on the deployment's configuration.

Ask for reviewed operational evidence before relying on backup schedules, recovery targets or incident-response commitments. This overview does not promise a recovery time or service level.

Trust Center evidence

Detailed trust statements, compliance information and service-provider disclosures are published only after evidence review and explicit approval. Each published statement carries its own scope and limitations.

Detailed Trust Center evidence is not currently available here. The product overview above is not a certification or a substitute for reviewed evidence.

Strictly necessary

Always active

Authentication, account security, requested work-session features, and remembering your consent choice. Limited, sanitized error reporting protects service reliability; it is not visitor analytics.

Privacy PolicyCookie Policy