Read-only by design, cloud-hosted or self-hosted, with SOC 2 in progress. How the connection works, where your data lives, what we test, who processes what, and how to get the report or the DPA.
Read-only by designThe query layer runs nothing but SELECT. No feature can write to your books.
Cloud or your own serverHosted and run by us, or self-hosted on the Private tier with no copy outside your network.
SOC 2 — in progressControls are in place and evidence collection is underway. Status is shared on request.
No third-party copyNo Constructelligence cloud copy of your financials, and no third party in the path.
How the connection works
Your systems are read through a login that can only select. Constructelligence maps what it reads into one model and hands back forecasts and answers; the connection has no write path at all.
The read-only guarantee
Every connector is inbound only. There is no write path to your ERP, your project system or your payroll platform.
The SQL layer refuses anything that is not a SELECT, so an accident cannot become a posting.
Connectors use a dedicated read-only login you create — Constructelligence never needs the owner role.
No feature writes back silently. If a future capability ever needs to, it will be a separate, explicitly-enabled connector, not a surprise.
The API binds to loopback on the Private tier and rejects any request that does not come from the machine itself, so it is unreachable over the network by default.
Every data API call needs a key (X-Api-Key); keys are compared as constant-time hashes and requests are rate limited per key.
Responses carry no-store caching plus clickjacking and MIME-sniffing protection.
There is no login page to phish: the app is not exposed to the internet. When it is deliberately fronted by a reverse proxy, that proxy owns authentication.
Where your data lives
CloudHosted and run by us
Nothing to install or patch. Your ERP and project data is read over read-only connections, and each customer's data is kept separate from every other's. The hosting region is named in your order form and in the DPA.
Hosting provider and region named in writing
Per-customer separation
New connectors and models arrive automatically
PrivateSelf-hosted on your server
For firms whose financials cannot leave their own network. Constructelligence runs on your machine or VM and reads your systems locally — there is no Constructelligence cloud copy and no third party in the path.
No data leaves your network
API bound to loopback by default
No subprocessors in the path of your data
SOC 2 — in progress
We are working through a SOC 2 programme now. The status below is the honest one; we will publish the report summary here the day it is issued.
ScopingTrust Services Criteria chosen and the system description written.
Controls in placeAccess control, change management, monitoring, backup and incident response.
SOC 2 Type IIn progress — evidence collection and readiness testing underway.
SOC 2 Type IIObservation window planned once Type I is issued.
Need the current status for a security review? Ask us and we will share where the programme has reached, in writing.
Penetration testing
Scope — the web app, the API, the connector credential path and the read-only query layer.
Cadence — at least annually and after any material change to a connector or to the API.
Findings — tracked to closure with an owner and a date; the report summary and the remediation log are available under NDA.
Today — the testing programme sits inside the SOC 2 work, so ask us for the current scope and status.
Subprocessors
Provider
Service
Customer data in the path?
Netlify
Serves this marketing site (a static export; no application data)
No
Cloud infrastructure
Runs the app and stores your deployment's data on the Cloud tier
Yes — Cloud tier only
Frontier model provider (optional)
Reads the text of a question when you deliberately enable remote questions — off by default
The question text only — never the database
Named providers and regions are listed here and updated before any change takes effect. On the Private (self-hosted) tier there are no subprocessors in the path of your data. The full list, with regions and DPAs, comes with the agreement and is available on request.
DPA, privacy and data use
A Data Processing Agreement is available for every paid tier, covering processing, subprocessors, security, breach notification and deletion.
We act as a processor for your financial data; the DPA documents transfers and the safeguards attached to them.
Deletion: on the Private tier, delete the data folder and the record is gone. On Cloud, deletion is confirmed in writing.
Retention is yours to set — the platform reads what your systems hold and stores only what a deployment needs.
We do not use one customer's data to train models for another. Any use of your data for model improvement is opt-in and written into the DPA.
These marketing pages carry no third-party analytics or advertising trackers.
Anything you submit through the beta form is stored on the deployment's own server — not sold, shared or synced anywhere.
Field-level and audit detail: see the security FAQ for the API, key handling and caching specifics.
Need something for a security review?The SOC 2 status, the penetration-test scope and summary, our DPA and the subprocessor list are all available in writing.Ask for the security pack
More of the platform
Your numbers are already there. Go look at them properly.
Hosted for you or self-hosted, read-only, every user included. Connected and reconciled against your own
reports in a single 90-minute session.