ConstructEther is in closed beta. This page sets out which obligations we meet today as a matter of law, which standards the platform is being designed against, and when independent assessment is targeted. Where a date appears it is a target rather than a commitment. We will not describe anything as certified until a certificate exists.
Status of this page. ConstructEther holds no security certification today. Nothing below has been independently assessed. The Compliance module, which carries document control and golden thread record keeping, is sequenced for 2027 to 2028 rather than built. If your procurement process requires a certificate on file before onboarding, we are not yet the right supplier and we would rather tell you now than at the end of a two-month process.
Data protection law that applies to us today, not a standard we opt into.
Document control aligned to ISO 19650 in the Compliance module, sequenced 2027 to 2028.
Bills of quantities generated against NRM2, as a draft for QS approval.
Controls designed against the standard. No certification held or audit booked.
UK Government cyber baseline. Assessment targeted before full launch.
Record keeping designed to support the golden thread. We do not certify compliance.
Type I then Type II, targeted after full launch. Nothing issued today.
AI management system standard. Tracked for adoption, no date committed.
Contractors face procurement, security and regulatory scrutiny that consumer AI tools were never designed for. Public sector frameworks demand it, the Building Safety Act shapes it, and your insurers will ask about it. We are building for that from the start, and we are not going to pretend we have arrived.
Enterprise procurement asks for ISO 27001, Cyber Essentials, data protection posture, sub-processor lists and incident response. We can answer how the platform is designed. We cannot yet hand you a certificate, and any supplier at our stage who says otherwise is worth a second look.
The Building Safety Act makes a continuous, accurate and accessible record mandatory for higher risk buildings. Our document layer is being designed for that, in the Compliance module, which is sequenced for 2027 to 2028. Accountability under the Act stays with the duty holders and their advisers.
Every figure the platform produces is traceable to the drawing it came from, with the working shown, and arrives as a draft for human approval. A surveyor signing off a measure needs to be able to check it, not take it on trust. That principle is in the product, not on a roadmap.
Each entry below states its status honestly. Statutory means the law applies to us today. Designed to means controls have been designed against a standard with no independent assessment. Targeted means a dated intention and nothing more. Detail is set out in the compliance pack, shared under NDA.
UK GDPR and the Data Protection Act 2018 apply to ConstructEther Limited as a matter of law. Our full position is set out in the privacy policy, which is the controlling document.
Security controls are being designed against ISO 27001. We hold no certificate, we have no audit booked, and we will not claim alignment as though it were certification.
The Compliance module is designed to keep a continuous, versioned and accessible record, aligned to ISO 19650, supporting the golden thread duty holders have to discharge. It is sequenced for 2027 to 2028 rather than built.
Bills of quantities are generated against NRM2, the rules a chartered surveyor already measures to. RICS regulates members and firms. ConstructEther is not RICS regulated and does not hold itself out as such.
Cyber Essentials Plus is the UK Government's certified baseline and an effective requirement for many public sector frameworks. Independent assessment is targeted before full launch. It has not taken place.
SOC 2 is the expected standard for North American enterprise procurement and increasingly asked for in the UK. Type I is targeted after full launch. Type II requires an observation window that has not started.
ISO/IEC 42001 is the first international management system standard for artificial intelligence. We are tracking it. No date is committed, partly because the pool of accredited certifiers is still small.
Standards are the surface. These are the principles the platform is being built around, and the ones your security and risk teams will want to test. Bring them to a call and we will go through each one with the engineer who wrote it.
Role based access as the default, scoped to the project and the package, with multi-factor authentication on administrative access.
Every quantity traceable to the drawing it came from, with the working shown, and the approval state recorded against the output.
Secure cloud infrastructure within UK and EU regions where possible. Bring your specific residency requirement and we will tell you whether we can meet it.
Designed so that one customer's data, prompts and outputs are not reachable from another, and so a contractor never sees a competitor's commercial data.
Human approval on every material output. Model and version recorded. Client data not used to train shared models without written consent.
Notification of a personal data breach within the statutory timeline under UK GDPR. The wider incident response process is being formalised as we scale.
Certifications cost money and take time, and doing them before there is a product to certify is theatre. The sequence below runs alongside the module rollout. Every date is a target and will move if the assessment does.
UK GDPR and DPA 2018 obligations met as a matter of law. Security controls designed against ISO 27001. Bills of quantities generated against NRM2, always as a draft for QS approval. Client data not used to train shared models.
Data processing agreements executed with Founding Partners. Sub-processor register published. Cyber Essentials Plus assessment booked with an assessor.
Cyber Essentials Plus assessment completed. ISO 27001 certification pursued. First independent penetration test commissioned. None of this is booked today, and we will update this page as each step is actually taken.
SOC 2 Type I, then a Type II observation window. ISO/IEC 42001 tracked as the pool of accredited certifiers matures. No dates committed, because committing to a date we cannot control is how this page stopped being useful last time.
No. We hold no security certification today and we have no audit booked. We meet UK GDPR and the Data Protection Act 2018 because the law requires it. Security controls are designed against ISO 27001 and Cyber Essentials, which is a design statement rather than a certificate. If your process requires a certificate on file before onboarding, we are not yet your supplier. We would rather say that on day one than at the end of a two-month procurement.
Secure cloud infrastructure within UK and EU regions where possible, which is the same wording as our privacy policy because the two should not disagree. We are not going to claim a hard region lock we cannot yet evidence to an auditor. Bring your specific residency requirement to the call and we will tell you plainly whether we can meet it today, at launch, or not at all.
No. Client data is not used to train shared AI models without explicit written consent. That commitment is in our privacy policy and it is the one item on this page we will not qualify.
Yes, and we expect to. Where you use the platform under an agreement with your own employer, your organisation may be the controller for project and commercial data with ConstructEther acting as processor on your instructions. Send us your standard DPA before the call and we will come back on it rather than improvising on the day.
Ask and we will share what we have. A published register with a notice period is on the list for the beta phase rather than something we can point you at today.
Not yet, in any direct sense. The Compliance module carries document control aligned to ISO 19650 and is designed to support golden thread record keeping, and it is sequenced for 2027 to 2028. It is a record keeping system rather than a certification, it is not a substitute for the principal designer or building control, and accountability under the Act stays with the duty holders and their advisers.
Not yet. An independent test is intended around full launch and no tester has been engaged. When a report exists we will say so here and share the executive summary under NDA.
Every output the platform produces carries a draft status until a person approves it, and the working is shown against the drawing it came from. What you disclose to your own client is a professional judgement for you and your regulator, not something we can decide for you, but the audit trail is there to support whatever position you take.
Shared under NDA with prospects, partners and procurement teams. It sets out the same positions as this page with the supporting detail, including what is not in place. Bring your security lead to the call and they can put the questions directly.
A note on language. Where we say statutory we mean an obligation that applies to us by law today. Where we say designed to we mean controls have been designed against a standard's requirements and no independent assessment has taken place. Where we say targeted or tracking we mean an intention with no assessment booked. We will only use the word certified once an accredited body has issued a certificate, and we will publish the certificate reference when it does.
RICS regulates its members and firms. ConstructEther is not RICS regulated and does not hold itself out as such. The platform does not certify, warrant or sign off any measurement, survey or valuation, and any output containing rates, quantities or a contractual position is a draft requiring quantity surveyor review. Nothing on this page is legal advice, and obligations under the Building Safety Act rest with the relevant duty holders and their own advisers.
ConstructEther Limited is a company registered in England and Wales, company number 17074549, registered at 4 The Rise, Thornton Le Dale, Pickering, YO18 7TG. Our full data protection position is set out in the privacy policy, which is the controlling document where this page and that one differ.