Enterprise-grade security for construction commercial data
Your contract values, CVR data, and commercial position are among your most sensitive assets. We protect them with the same rigour you apply to your project delivery.
Encryption
All data stored in MeasureDeck is encrypted at rest using AES-256 encryption. All data in transit is protected using TLS 1.3. Encryption keys are managed using hardware security modules (HSMs) with key rotation policies. Backups are encrypted before storage and tested quarterly.
- AES-256 encryption at rest for all project data, documents, and evidence
- TLS 1.3 enforced for all data in transit — no fallback to weaker protocols
- HSM-backed key management with automated annual rotation
- Encrypted database backups with point-in-time recovery
Encryption
Data Hosting & Residency
Your commercial project data stays in the United Kingdom. We use UK-region Supabase PostgreSQL instances hosted in AWS eu-west-2 (London). Document storage is provisioned in Cloudflare R2 with UK region selection. We do not transfer primary project data outside the UK without your explicit consent.
- Primary database: AWS eu-west-2 (London) via Supabase
- Document and evidence storage: Cloudflare R2 with EU-west region
- No cross-border transfer of primary project data
- Data residency confirmations available for Enterprise accounts
Data Hosting & Residency
Access Control
MeasureDeck uses role-based access control (RBAC) throughout. Every user is assigned a role — Owner, Admin, Commercial Manager, or Viewer — and each role has tightly defined permissions. External collaborators (supply chain partners) receive a restricted external role with access limited to their specific work packages.
- Role-based access control with four built-in roles
- Row-level security enforced at database level — users cannot access data outside their workspace
- Multi-factor authentication (MFA) supported and recommended
- SSO / SAML 2.0 available for Enterprise accounts
- Session management with configurable timeout policies
Access Control
Audit Logging
Every action in MeasureDeck — view, create, edit, delete, export — is recorded in an immutable audit log. The audit log is a critical tool for dispute resolution, compliance review, and security investigations. Logs are retained for a minimum of 7 years and are tamper-proof.
- Immutable audit trail for every create, edit, delete, and export action
- Logs include user identity, timestamp, IP address, and action detail
- 7-year minimum retention for compliance and dispute purposes
- Audit log export available for GDPR data subject access requests
- Real-time alerts for suspicious activity patterns
Audit Logging
Application Security
Our development process incorporates security at every stage. We conduct regular penetration testing, dependency audits, and code reviews. Our infrastructure is managed using infrastructure-as-code with automated security scanning in the CI/CD pipeline.
- Annual third-party penetration testing with remediation tracking
- Automated SAST and dependency vulnerability scanning in CI/CD
- OWASP Top 10 addressed in development guidelines
- Responsible disclosure programme — security@measuredeck.com
- SOC 2 Type II certification in progress
Application Security
Compliance & Certifications
MeasureDeck is built for compliance with UK data protection law. We maintain a full Record of Processing Activities (ROPA), have documented Data Processing Agreements with all sub-processors, and implement Privacy by Design across all product development.
- UK GDPR and Data Protection Act 2018 compliant
- ICO registration maintained
- Data Processing Agreements (DPAs) available for all customers
- Sub-processor list published and updated — measuredeck.com/subprocessors
- Privacy Impact Assessments (PIAs) conducted for new features
Compliance & Certifications
Certifications & Compliance
Our security posture is independently validated and transparently disclosed.
UK GDPR Compliant
ActiveFull compliance with UK GDPR and the Data Protection Act 2018.
ICO Registered
ActiveRegistered with the Information Commissioner's Office as a data controller.
SOC 2 Type II
In ProgressSOC 2 Type II audit in progress. Expected completion Q3 2026.
ISO 27001
PlannedISO 27001 certification planned as part of our 2026 security roadmap.
Cyber Essentials
ActiveNCSC Cyber Essentials certification held and renewed annually.
256-bit Encryption
ActiveAES-256 at rest, TLS 1.3 in transit, HSM-backed key management.
Sub-processor Transparency
We maintain a complete, up-to-date list of every sub-processor we use. You can review this list at any time and will be notified of any changes.
Contact our security team
For security questionnaires, penetration test reports, DPA requests, or to report a vulnerability — our security team responds within one business day.