Security
Security and data trust
Construction data is commercially sensitive. These are the commitments that govern how Cornerstone handles it. As an early-stage company, we state practice as it is implemented—not as aspiration.
Customer data ownership
Customers own their project data. Cornerstone processes it to provide the service and does not sell it or share it with other customers.
Access control
Access to customer data is restricted to personnel who need it to deliver the service, under role-based access controls and audit logging.
Encryption
Customer data is encrypted in transit and at rest using industry-standard protocols.
Data isolation
Each customer's project data is logically isolated. One customer's data is not visible to another.
Use of customer data for model improvement
Whether and how a customer's data may contribute to model improvement is governed by the customer agreement. Cross-project learning within a customer's own portfolio is configured with the customer. We do not use one customer's data to benefit another without explicit agreement.
Retention and deletion
Data is retained for the duration of the agreement and deleted or returned on termination, subject to legal requirements.
Auditability and recommendation records
Recommendations, their inputs, and the decisions taken on them are recorded so they can be reviewed and reproduced. Human review remains part of the operating model.
Subprocessors
A current list of subprocessors is available to customers and prospective customers on request.
Incident response
We maintain an incident-response process and notify affected customers without undue delay in the event of a security incident affecting their data.
Questions
Security reviews and detailed technical diligence are supported for prospective customers under confidentiality. Use the contact form to begin.