What we can prove, and what we can't yet.

Most trust pages print a row of badges and let you assume somebody checked them. This one puts a status on every claim instead, because the difference between “an auditor verified this” and “we say so” is the entire question you came here to answer.

Last reviewed 19 August 2026

Verifiable by you

A property of how the system is built, not a promise we make about it. Your own team can confirm it without taking our word for anything.

Self-attested

We assert this and stand behind it contractually. No independent third party has audited it. Read it as our word, not an auditor's.

In progress

Actively underway. Listed here so you can see what's coming, with the honest status attached. Not yet something you should rely on.

Planned

On the roadmap, not started. Listed so you can ask us about timing rather than guess.

Four things you don't have to take our word for.

These hold because of how the system is built, not because we promise them. Each one lists how to check it yourself.

No network path off the box

Verifiable

In the air-gapped configuration the hardware has no route to the public internet. Radios are disabled in firmware, there is no telemetry channel and no phone-home. Model and platform updates arrive on media your team inspects first.

How to verify

Put it on a monitored segment and watch. There is nothing to see, and that's the point — this is testable in an afternoon with tools you already own.

Inference happens on your hardware

Verifiable

Every drawing, contract, daily log and voice note is read by a model running on the machine in your building. There is no vendor-side inference in the path because there is no vendor in the path.

How to verify

Pull the uplink and keep working. The platform doesn't degrade, because nothing it needs was ever on the other end of that cable.

The weights sit on your disks

Verifiable

Open-weight models, installed locally. No licence server to reach, no entitlement check, and no vendor able to deprecate the model your procurement was written around.

How to verify

Inspect the filesystem. The weights are files. Copy them, hash them, hold them in escrow if your contract calls for it.

The audit log is yours and it's local

Verifiable

Every prompt, retrieval and generation is written to an on-box log alongside the project record it touched. An access-to-information request, an inquiry or an internal review can be answered from your own logs without asking us for anything.

How to verify

Read it directly. It's on your storage, in your facility, under your retention policy — not exported from a vendor dashboard.

These apply to the on-premise and air-gapped configurations described on the hardware page.

Where we actually stand.

Including the ones we don't have. A certification you can't click through to verify is one we haven't earned yet, and we'd rather you read that here than find it out in a registry search during procurement.

CSA STAR Level 1

Cloud Security Alliance

In progress

A self-assessment against the Consensus Assessments Initiative Questionnaire, published to the CSA's public STAR registry. Level 1 is self-attested by design: the CSA publishes what we submit, it does not audit it.

Our registry entry will be linked here once it is live. Until you can click through to it, treat this as not yet done.

CyberSecure Canada

Innovation, Science and Economic Development Canada

In progress

The federal certification for Canadian small and medium businesses, covering thirteen control areas from patching and backups to incident response and access control. Self-assessment first, then confirmation by an accredited certification body.

Relevant to Canadian public sector procurement specifically, which is why it's ahead of the heavier international standards on our list.

SOC 2 Type II

Independent CPA firm, AICPA standards

Planned

An attestation report produced by a licensed CPA firm covering a continuous observation window, typically three to twelve months. It cannot be self-issued and there is no such thing as a SOC 2 certificate.

We are not SOC 2 audited and we don't describe ourselves as SOC 2 ready, aligned or equivalent. When we have a report, this line will say so and we'll share it under NDA.

ISO/IEC 27001

Accredited certification body

Planned

Certification of an information security management system by an accredited body. Like SOC 2, it requires an external auditor and cannot be self-declared.

NIST SP 800-171 self-assessment

Self-assessed, scored in SPRS

Planned

The control set for handling Controlled Unclassified Information in the US federal supply chain. Contractors self-assess and post a score. Being genuinely self-attested does not make it low-stakes: a false score is a False Claims Act exposure.

Sequenced behind the Canadian items because it only matters once we pursue US federal work.

If we hold your data, here's what we do with it.

Everything below is self-attested. We stand behind it contractually, but no external auditor has tested it, and this page is not going to pretend otherwise.

Zero retention with every AI provider

Self-attested

Content sent to a model provider for processing is covered by a zero-retention agreement. Providers do not store it beyond the moment of processing and do not train on it.

Encrypted in transit and at rest

Self-attested

Project documentation is commercially sensitive and is encrypted both on the wire and in storage.

Role-based access control

Self-attested

Access to project records is scoped by role, so a subcontractor seat cannot read what an owner's rep can.

Audit logging

Self-attested

Access to and changes against project records are logged, which is also what makes the revision chain and the delay evidence work.

No training on your data without consent

Self-attested

We do not use your project content to train models, and we will not without your explicit, separately obtained agreement.

Deletion on request

Self-attested

Close your account and we delete your project data on request, subject only to limited retention the law requires of us, such as billing records.

Data handling, your rights under PIPEDA, the GDPR and the CCPA, and how to exercise them are set out in full in our privacy policy.

Found something? Tell us.

Email dev@construction.live. A real person reads it.

What we commit to

  • We acknowledge reports within two business days.
  • We will not pursue legal action against good-faith research that respects the boundaries below.
  • We'll tell you when the issue is fixed, and credit you publicly if you'd like us to.

What we ask of you

  • Test only against your own account or a deployment you're authorised to touch.
  • No denial of service, no social engineering, no physical attempts against our staff or offices.
  • Don't access, modify or retain another customer's project data. If you reach it by accident, stop and tell us.

Got a security questionnaire?

Send it over. We'll fill it in properly, and we'll write “no” where the answer is no.