Security
What protects your documents and records, stated plainly.
Tender documents and quality records are commercially sensitive. This page lists the controls that are in place today, and our compliance status as it actually is.
Access
- Invitation-only accounts
- There is no public sign-up. Organizations and their members are provisioned by us, and an identity that has not been provisioned is refused.
- Single sign-on
- Sign-in runs through WorkOS AuthKit, with email and password, one-time email codes, or Google accounts.
- Roles
- Fennec separates owners, admins, members and viewers. Chainage separates engineers, approvers, quantity surveyors and administrators, and checks roles on the server.
- Organization scoping
- Documents, extractions, inspections and results belong to an organization, and requests are authorized against the organization in the signed-in session.
Data
- Encryption in transit
- All traffic is served over HTTPS, with HTTP Strict Transport Security on our web domains.
- Encryption at rest
- Documents are stored in Amazon S3 and records in managed PostgreSQL, both encrypted at rest by the provider.
- Hosting
- Both products run on Amazon Web Services, with web applications served through Vercel. We share region details on request.
- Model training
- Fennec does not train models on your documents. It sends them to third-party document-parsing and language-model services for processing, which we can list for your review.
Records you can rely on
- Chainage audit logs
- Append-only logs record who changed each record and who opened each inspection. They cannot be edited from the product.
- Rules frozen at the time of work
- A Chainage inspection keeps the acceptance limits it was raised under, so later catalogue changes never re-judge past work.
- Corrections alongside originals
- When a reviewer corrects a value Fennec extracted, the original value and its citation are kept next to the correction.
Compliance status
fluidzero does not currently hold SOC 2 or ISO 27001 certification. We would rather tell you that than show a badge we have not earned.
We complete security questionnaires, walk your team through our architecture and data flows, list the third-party services that process your data, and discuss contractual data-protection terms. Email hrishikeshkakkad@fluidzero.ai to start a review.
Reporting a vulnerability
If you believe you have found a security issue in any fluidzero product or website, email hrishikeshkakkad@fluidzero.ai with the details. Please give us reasonable time to fix it before disclosing it. See also our privacy policy.