Trust & Security
Project Information Deserves Professional Protection.
Controlled access, structured confidentiality, and accountable project workflows.
Construction drawings, technical reports, calculations, credentials, communications, and project records may contain confidential or commercially sensitive information. ConstructVerify is designed around controlled access, role separation, confidentiality, and accountable project workflows.
Role Separation
- projects
- submissions
- invoices
- review reports
- revisions
- messages
- approved deliverables
- projects and documents specifically assigned to them for authorized review
- project intake
- assignments
- quality assurance
- deliverables
- payments
- platform operations
Controlled Communication Model
Allowed
Client ↔ ConstructVerify Admin
Reviewer ↔ ConstructVerify Admin
Not Allowed
Client ↔ Reviewer
This controlled communication model helps protect:
- reviewer independence
- confidentiality
- platform integrity
- professional accountability
Security Architecture
Document access
Project documents should be accessible only to users whose roles and assignments authorize that access.
What the architecture is intended to support
- private document storage
- controlled file access
- user authentication
- role-based authorization
- time-limited access where appropriate
- activity and audit logging
- administrative oversight
Reviewer credentials
Professional credentials and identity documentation submitted by reviewers are treated as restricted account information and should not be exposed to clients or other reviewers.
Payment information
ConstructVerify does not intend to store full payment-card credentials directly.
Payments are processed through approved third-party payment providers according to the payment methods available to the client.
Ongoing responsibility
No internet-based platform can guarantee absolute security.
ConstructVerify therefore treats security as an ongoing operational responsibility involving technology, procedures, access controls, monitoring, provider management, and continuous improvement.
Data Processing Addendum
Formal processor terms for enterprise due diligence. Version 1.0 — effective October 1, 2026.
Reporting a Security Concern
Please do not publicly disclose a suspected vulnerability before providing ConstructVerify a reasonable opportunity to investigate.
Trust Center — In Development
These areas are being prepared and will be published only once the underlying capabilities are implemented and verified. ConstructVerify does not claim certifications it does not hold.
- Security OverviewPlanned
- Platform Availability / StatusPlanned
- SubprocessorsPlanned
- Data ProcessingPlanned
- Incident ResponsePlanned
- Data ResidencyPlanned
- Compliance CertificationsPlanned