Trust and compliance

Designed to the standards your procurement team will ask for.
None of them certified yet.

ConstructEther is in closed beta. This page sets out which obligations we meet today as a matter of law, which standards the platform is being designed against, and when independent assessment is targeted. Where a date appears it is a target rather than a commitment. We will not describe anything as certified until a certificate exists.

Status of this page. ConstructEther holds no security certification today. Nothing below has been independently assessed. The Compliance module, which carries document control and golden thread record keeping, is sequenced for 2027 to 2028 rather than built. If your procurement process requires a certificate on file before onboarding, we are not yet the right supplier and we would rather tell you now than at the end of a two-month process.

Statutory obligation

UK GDPR and DPA 2018

Data protection law that applies to us today, not a standard we opt into.

Designed to

ISO 19650

Document control aligned to ISO 19650 in the Compliance module, sequenced 2027 to 2028.

Designed to

NRM2

Bills of quantities generated against NRM2, as a draft for QS approval.

Designed to

ISO/IEC 27001:2022

Controls designed against the standard. No certification held or audit booked.

Targeted

Cyber Essentials Plus

UK Government cyber baseline. Assessment targeted before full launch.

Designed to

Building Safety Act 2022

Record keeping designed to support the golden thread. We do not certify compliance.

Targeted

SOC 2

Type I then Type II, targeted after full launch. Nothing issued today.

Tracking

ISO/IEC 42001

AI management system standard. Tracked for adoption, no date committed.

Why this matters

Construction cannot afford uncontrolled AI.

Contractors face procurement, security and regulatory scrutiny that consumer AI tools were never designed for. Public sector frameworks demand it, the Building Safety Act shapes it, and your insurers will ask about it. We are building for that from the start, and we are not going to pretend we have arrived.

01 · Procurement

The security questionnaire will come.

Enterprise procurement asks for ISO 27001, Cyber Essentials, data protection posture, sub-processor lists and incident response. We can answer how the platform is designed. We cannot yet hand you a certificate, and any supplier at our stage who says otherwise is worth a second look.

02 · Regulation

The golden thread is not optional.

The Building Safety Act makes a continuous, accurate and accessible record mandatory for higher risk buildings. Our document layer is being designed for that, in the Compliance module, which is sequenced for 2027 to 2028. Accountability under the Act stays with the duty holders and their advisers.

03 · Liability

AI output should be auditable.

Every figure the platform produces is traceable to the drawing it came from, with the working shown, and arrives as a draft for human approval. A surveyor signing off a measure needs to be able to check it, not take it on trust. That principle is in the product, not on a roadmap.

The standards in detail

What we can say, and what we cannot.

Each entry below states its status honestly. Statutory means the law applies to us today. Designed to means controls have been designed against a standard with no independent assessment. Targeted means a dated intention and nothing more. Detail is set out in the compliance pack, shared under NDA.

Statutory obligation
UK GDPR · DPA 2018

Data protection and privacy

UK GDPR and the Data Protection Act 2018 apply to ConstructEther Limited as a matter of law. Our full position is set out in the privacy policy, which is the controlling document.

  • Lawful basis statedContractual necessity, legitimate interests, legal obligation and consent, as set out in the privacy policy.
  • No training on client dataClient data is not used to train shared AI models without explicit written consent.
  • Data subject rightsAccess, rectification, erasure, restriction, portability and withdrawal of consent, handled within statutory timelines.
  • Data residencySecure cloud infrastructure within UK and EU regions where possible. Residency requirements can be discussed on a call.
Designed to · not certified
ISO/IEC 27001:2022

Information security

Security controls are being designed against ISO 27001. We hold no certificate, we have no audit booked, and we will not claim alignment as though it were certification.

  • Role based accessLeast privilege by default, with access scoped to the project and the package.
  • EncryptionData encrypted in transit and at rest.
  • Secure developmentSecurity designed in from the first commit rather than retrofitted before an audit.
  • CertificationNot held. Targeted after full launch. We will publish the certificate number when there is one.
Designed to · sequenced
Building Safety Act 2022 · ISO 19650

Document control and the golden thread

The Compliance module is designed to keep a continuous, versioned and accessible record, aligned to ISO 19650, supporting the golden thread duty holders have to discharge. It is sequenced for 2027 to 2028 rather than built.

  • Versioned document recordVersion history and access log against every document. Design intent, not yet shipped.
  • Exportable evidenceRecords exportable as an evidence pack for the duty holder to submit.
  • What it is notNot a certification, not a substitute for the principal designer or building control, and not a defence in itself.
  • Where accountability sitsWith the duty holders under the Act and their own advisers. Not with a software supplier.
Designed to
RICS · NRM2

Professional standards alignment

Bills of quantities are generated against NRM2, the rules a chartered surveyor already measures to. RICS regulates members and firms. ConstructEther is not RICS regulated and does not hold itself out as such.

  • NRM2 structureBills generated against NRM2 rather than SMM7.
  • Draft for approvalEvery output carries a draft status until a surveyor approves it. Nothing is committed on the member's behalf.
  • Working shownEach quantity is traceable to the drawing it came from, so the measure can be checked rather than trusted.
  • Never certifiedThe platform does not certify, warrant or sign off a measurement, survey or valuation.
Targeted
NCSC Cyber Essentials Plus

UK Government cyber baseline

Cyber Essentials Plus is the UK Government's certified baseline and an effective requirement for many public sector frameworks. Independent assessment is targeted before full launch. It has not taken place.

  • Access control and MFALeast privilege by default, with multi-factor authentication on administrative access.
  • Secure configurationHardened baseline configuration and a default deny posture.
  • PatchingDefined patching approach for platform dependencies.
  • AssessmentNot yet scheduled with an assessor. We will say so plainly when it is booked.
Targeted · after full launch
AICPA · SOC 2

SOC 2 Type I and Type II

SOC 2 is the expected standard for North American enterprise procurement and increasingly asked for in the UK. Type I is targeted after full launch. Type II requires an observation window that has not started.

  • Nothing issuedNo Type I attestation and no Type II report exists today.
  • SequenceType I first, then a Type II observation window, then a report.
  • AuditorNot yet engaged. We will name the firm once one is appointed.
  • If you need one nowYou should not wait for us. Tell us on the call and we will be straight about whether the timing works.
Tracking
ISO/IEC 42001:2023

AI management system

ISO/IEC 42001 is the first international management system standard for artificial intelligence. We are tracking it. No date is committed, partly because the pool of accredited certifiers is still small.

  • Human approval by defaultAI output is a draft for human approval. This is a product rule rather than a policy statement.
  • ProvenanceModel and version recorded against the output, so a figure can be traced back.
  • Intended useDocumented scope and acceptable use per capability.
  • CertificationNot pursued yet. Tracking only.
Design principles

The architecture underneath the standards.

Standards are the surface. These are the principles the platform is being built around, and the ones your security and risk teams will want to test. Bring them to a call and we will go through each one with the engineer who wrote it.

Identity and access

Role based access as the default, scoped to the project and the package, with multi-factor authentication on administrative access.

Traceability

Every quantity traceable to the drawing it came from, with the working shown, and the approval state recorded against the output.

Data residency

Secure cloud infrastructure within UK and EU regions where possible. Bring your specific residency requirement and we will tell you whether we can meet it.

Separation

Designed so that one customer's data, prompts and outputs are not reachable from another, and so a contractor never sees a competitor's commercial data.

AI governance

Human approval on every material output. Model and version recorded. Client data not used to train shared models without written consent.

Incident response

Notification of a personal data breach within the statutory timeline under UK GDPR. The wider incident response process is being formalised as we scale.

Compliance trajectory

Sequenced against the product, not against a sales cycle.

Certifications cost money and take time, and doing them before there is a product to certify is theatre. The sequence below runs alongside the module rollout. Every date is a target and will move if the assessment does.

Now · closed beta

Foundation

UK GDPR and DPA 2018 obligations met as a matter of law. Security controls designed against ISO 27001. Bills of quantities generated against NRM2, always as a draft for QS approval. Client data not used to train shared models.

UK GDPR · statutory NRM2 · in the product ISO 27001 · designed to
Through beta · target

Founding Partner agreements

Data processing agreements executed with Founding Partners. Sub-processor register published. Cyber Essentials Plus assessment booked with an assessor.

DPAs · target Sub-processors · target
Around full launch · target

First certifications

Cyber Essentials Plus assessment completed. ISO 27001 certification pursued. First independent penetration test commissioned. None of this is booked today, and we will update this page as each step is actually taken.

Cyber Essentials Plus · target ISO 27001 · target
After launch · intention

SOC 2 and beyond

SOC 2 Type I, then a Type II observation window. ISO/IEC 42001 tracked as the pool of accredited certifiers matures. No dates committed, because committing to a date we cannot control is how this page stopped being useful last time.

SOC 2 · intention ISO 42001 · tracking
Procurement questions

What security teams actually ask.

Are you certified?

No. We hold no security certification today and we have no audit booked. We meet UK GDPR and the Data Protection Act 2018 because the law requires it. Security controls are designed against ISO 27001 and Cyber Essentials, which is a design statement rather than a certificate. If your process requires a certificate on file before onboarding, we are not yet your supplier. We would rather say that on day one than at the end of a two-month procurement.

Where is our data stored, and can it leave the UK?

Secure cloud infrastructure within UK and EU regions where possible, which is the same wording as our privacy policy because the two should not disagree. We are not going to claim a hard region lock we cannot yet evidence to an auditor. Bring your specific residency requirement to the call and we will tell you plainly whether we can meet it today, at launch, or not at all.

Is our project data used to train AI models?

No. Client data is not used to train shared AI models without explicit written consent. That commitment is in our privacy policy and it is the one item on this page we will not qualify.

Will you sign our DPA?

Yes, and we expect to. Where you use the platform under an agreement with your own employer, your organisation may be the controller for project and commercial data with ConstructEther acting as processor on your instructions. Send us your standard DPA before the call and we will come back on it rather than improvising on the day.

Can we have your sub-processor list?

Ask and we will share what we have. A published register with a notice period is on the list for the beta phase rather than something we can point you at today.

How does the platform support Building Safety Act obligations?

Not yet, in any direct sense. The Compliance module carries document control aligned to ISO 19650 and is designed to support golden thread record keeping, and it is sequenced for 2027 to 2028. It is a record keeping system rather than a certification, it is not a substitute for the principal designer or building control, and accountability under the Act stays with the duty holders and their advisers.

Do you penetration test?

Not yet. An independent test is intended around full launch and no tester has been engaged. When a report exists we will say so here and share the executive summary under NDA.

How is AI use disclosed in what we send to a client?

Every output the platform produces carries a draft status until a person approves it, and the working is shown against the drawing it came from. What you disclose to your own client is a professional judgement for you and your regulator, not something we can decide for you, but the audit trail is there to support whatever position you take.

Compliance pack

Want the detail behind any of this?

Shared under NDA with prospects, partners and procurement teams. It sets out the same positions as this page with the supporting detail, including what is not in place. Bring your security lead to the call and they can put the questions directly.

A note on language. Where we say statutory we mean an obligation that applies to us by law today. Where we say designed to we mean controls have been designed against a standard's requirements and no independent assessment has taken place. Where we say targeted or tracking we mean an intention with no assessment booked. We will only use the word certified once an accredited body has issued a certificate, and we will publish the certificate reference when it does.

RICS regulates its members and firms. ConstructEther is not RICS regulated and does not hold itself out as such. The platform does not certify, warrant or sign off any measurement, survey or valuation, and any output containing rates, quantities or a contractual position is a draft requiring quantity surveyor review. Nothing on this page is legal advice, and obligations under the Building Safety Act rest with the relevant duty holders and their own advisers.

ConstructEther Limited is a company registered in England and Wales, company number 17074549, registered at 4 The Rise, Thornton Le Dale, Pickering, YO18 7TG. Our full data protection position is set out in the privacy policy, which is the controlling document where this page and that one differ.