Frequently asked questions

Short answers to the questions we are asked most, with links to the long ones.

About the product

What does CARDO actually do?

Keeps a risk register, estimates it from a managed rate card, runs Monte Carlo simulation for cost and schedule, and produces a board-ready PDF report from the result. See the product overview for the full picture, or Getting started if you already have access.

Can I sign up myself?

No. CARDO is invite-only: an administrator at your company adds you. If you need access and have not received an invitation, ask whoever manages your company’s account, or request access if your company has not set one up yet.

What file formats can I import a programme from?

Primavera P6 XER (.xer) and Microsoft Project XML (.xml). Native .mpp files and Asta Powerproject exports are not read directly — export to one of the two supported formats first. See Importing a programme.

Your data

Who owns the risk data I put into CARDO?

Your organisation. Your employer holds the account and, in data protection terms, is the controller for the commercial and programme data in the system; CARDO acts as the processor. The full detail is in the privacy policy.

Can I export my data if we stop using CARDO?

Reports export as PDF at any time from within the product. For a full export of register, rates and schedule data, contact us — we would rather help you get it out cleanly than have that be a reason not to try the product.

Security and compliance

Are you SOC 2 or ISO 27001 certified?

Not yet. We run a readiness programme aligned to both, and we say exactly where that stands, without a badge or a claim we cannot back up, on the Trust Centre.

Do you support single sign-on (SSO)?

Not yet for SAML SSO or SCIM provisioning. Accounts are invite-only with optional two-factor authentication in the meantime. If SSO is a requirement for your rollout, tell us — it helps us prioritise it.

How is my data encrypted?

In transit with TLS, and at rest by the underlying cloud platform. See the Trust Centre for the full list of controls in place, including tenant isolation, role-based access and audit logging.

Getting help

Something in the product does not match what a guide says.

Tell us. These guides are written against the current product, not a plan for it, so a mismatch is either a bug or a guide we have not updated yet — either way we want to know.

How do I contact support?

Use the contact page. Include what you were trying to do, what happened instead, and a screenshot if the issue is visual — it gets you an answer faster than a description alone.

Still stuck?

Tell us what you were trying to do and what happened instead. A screenshot of the page helps more than a description of it.