How your programme is handled.
A programme can show how a contractor plans to win or defend money. This page says plainly what happens to one when you upload it.
In transit
Every request to the hosted service, including uploads and downloads, travels over HTTPS. TLS is terminated by our hosting provider.
Where it lives
The hosted service runs in the EU (Frankfurt). Uploaded files are stored on disk there, each under a random session identifier, together with the settings you save against them, such as a risk register or NEC4 Contract Data.
How long it's kept
A workspace's projects are kept while it is on a paid plan. When a paid plan ends, they are kept for 30 days and then deleted, and the workspace's owners are emailed at least a week before. A Free workspace's projects are deleted after 30 days without being opened. Owners, admins and members can delete a project at any time.
On a dedicated or on-premise instance, your administrator decides how long uploads are kept, and can delete stored uploads older than a chosen age at any time.
Who can see it
- Accounts: passwords are stored only as salted scrypt hashes, never in plain text.
- Roles: viewer, planner and administrator, with each tab and download switched on or off per role, enforced by the server.
- Activity-level access: a user can be limited to WBS branches or activity-code values. It's enforced on the server for every request, so hidden work can't be reached by calling the API directly.
- Sign-in controls: sign-in length, password rules, lockout after failed attempts, forced password change, and signing everyone else out.
- Activity log: sign-ins, failures, account and settings changes, uploads and downloads of repaired files, exportable as CSV.
What we do with it
We analyse your programme to show you the results. We don't sell it, share it, or use it to train anything. The public demo runs only on a fictional programme we built for the purpose.
Keeping it in-house
Enterprise customers can have a dedicated instance, or install the application on their own servers or a Windows machine, where nothing leaves their network.
GDPR
A programme file usually contains little personal data: typically resource names and activity-code values such as a responsible person's name. Where we process personal data on your behalf, we act as processor and you as controller.
Sub-processors
| Provider | Purpose | Where | Status |
|---|---|---|---|
| Render | Application hosting and storage of uploads | EU (Frankfurt) | In use |
| Supabase | Accounts and the application database | EU (London or Frankfurt) | From launch of accounts |
| Stripe | Payments, invoices and VAT | EU and US | From launch of subscriptions |
| Resend | Transactional email | To be confirmed | From launch of accounts |
| Plausible | Cookie-less website analytics, no personal data | EU | Planned, website only |
Reporting a vulnerability
If you think you've found a security problem, please tell us before telling anyone else.