Trust & Security

Project Information Deserves Professional Protection.

Controlled access, structured confidentiality, and accountable project workflows.

Construction drawings, technical reports, calculations, credentials, communications, and project records may contain confidential or commercially sensitive information. ConstructVerify is designed around controlled access, role separation, confidentiality, and accountable project workflows.

Role Separation

Clients
  • projects
  • submissions
  • invoices
  • review reports
  • revisions
  • messages
  • approved deliverables
Reviewers
  • projects and documents specifically assigned to them for authorized review
Administrators
  • project intake
  • assignments
  • quality assurance
  • deliverables
  • payments
  • platform operations

Controlled Communication Model

Allowed

Client ↔ ConstructVerify Admin

Reviewer ↔ ConstructVerify Admin

Not Allowed

Client ↔ Reviewer

This controlled communication model helps protect:

  • reviewer independence
  • confidentiality
  • platform integrity
  • professional accountability

Security Architecture

Document access

Project documents should be accessible only to users whose roles and assignments authorize that access.

What the architecture is intended to support
  • private document storage
  • controlled file access
  • user authentication
  • role-based authorization
  • time-limited access where appropriate
  • activity and audit logging
  • administrative oversight
Reviewer credentials

Professional credentials and identity documentation submitted by reviewers are treated as restricted account information and should not be exposed to clients or other reviewers.

Payment information

ConstructVerify does not intend to store full payment-card credentials directly.

Payments are processed through approved third-party payment providers according to the payment methods available to the client.

Ongoing responsibility

No internet-based platform can guarantee absolute security.

ConstructVerify therefore treats security as an ongoing operational responsibility involving technology, procedures, access controls, monitoring, provider management, and continuous improvement.

Data Processing Addendum

Formal processor terms for enterprise due diligence. Version 1.0 — effective October 1, 2026.

Reporting a Security Concern

security@constructverify.com

Please do not publicly disclose a suspected vulnerability before providing ConstructVerify a reasonable opportunity to investigate.

Trust Center — In Development

These areas are being prepared and will be published only once the underlying capabilities are implemented and verified. ConstructVerify does not claim certifications it does not hold.

  • Security OverviewPlanned
  • Platform Availability / StatusPlanned
  • SubprocessorsPlanned
  • Data ProcessingPlanned
  • Incident ResponsePlanned
  • Data ResidencyPlanned
  • Compliance CertificationsPlanned