Skip to content
Trust & security

Controls for construction operators

Privacy, access, labour-compliance awareness and clear service boundaries — without fake certifications.

GDPRIn force

EU data protection for B2B contacts and ops data

What we put in placeLawful bases, retention, processor awareness and rights-ready responses.
What you gainClear controller identity and privacy policy.
Access controlOperating practice

Identities, joiners and leavers

What we put in placeIdentity hygiene, least privilege and subcontractor access patterns.
What you gainFewer orphan accounts when people leave packages.
Labour awarenessEducational

Cross-border workforce education

What we put in placeChecklists and process language around posting concepts — not a guarantee of inspection outcomes.
What you gainFewer blind spots before mobilisation.
Audit trailsControl design

Evidence for management and partners

What we put in placeLogging and document trails for project and system changes where in scope.
What you gainSomething to show when questions arrive.
BoundariesPolicy

Honest service claims

What we put in placeClear disclaimers (no fake ISO logos; no statutory auditor claim unless licensed).
What you gainTrust from precision, not theatre.

Security practices

We size security to mid-market construction reality: protect access, backups awareness and vendor hygiene — without enterprise theatre nobody funds.

  • MFA and least-privilege where systems allow
  • Backup and recovery awareness in support scopes
  • Vendor and admin access reviewed on cadence
  • Incident communication path agreed with the client

Data residency

Default preference for EU/EEA processing for client operational data we handle. Transfers use appropriate safeguards when required.

Talk about controls