Security

CARDO holds commercially sensitive cost and programme data for infrastructure projects. This page describes how that data is protected and where we currently stand on compliance, so a security review can start without waiting on us.

Looking for product documentation instead? Visit the Help Centre.

Controls in place

Tenant isolation

Every read and write is scoped to an organisation and checked on the server before the query runs. Access is enforced in server-side guards rather than in the browser, so a modified client cannot reach another tenant’s data.

Role-based access

Four project roles (Admin, Risk Manager, QS Estimator, Viewer) and three organisation roles (Owner, Org Admin, Member) resolve to a capability set that gates both the interface and the server action behind it.

Encryption

Data is encrypted in transit with TLS and at rest by the underlying Google Cloud platform. HSTS is enabled with preload.

Audit trail

Changes to risk records write an append-only audit entry recording who changed what and when. Entries are signed to make tampering detectable and streamed to immutable managed storage.

Authentication

Session cookies are HttpOnly, Secure and SameSite, and expire after 14 days. Time-based one-time password multi-factor authentication is available per account.

Application hardening

Cross-site request forgery protection on state-changing requests, per-endpoint rate limiting, a strict Content Security Policy, and X-Frame-Options set to DENY.

Where we are on compliance

We would rather tell you this plainly than have you find it in a questionnaire.

SOC 2 Type II
Readiness programme in progress. Controls are documented and implemented internally. We have not completed an external audit and are not certified. We will say so here on the day that changes.
ISO 27001
Not certified.
UK GDPR
Compliance programme in place. See the privacy policy and the DPA, both published rather than gated.
Single sign-on
SAML SSO and SCIM provisioning are not yet available. Accounts are invite-only and administered per organisation, with optional multi-factor authentication. Tell us if SSO is a requirement for your rollout.
Penetration test
Available to discuss under NDA. Contact us for the current position.

Reporting a vulnerability

Email TODO_SECURITY_EMAIL with enough detail to reproduce the issue. We will acknowledge within two working days and keep you updated until it is resolved. Please do not test against production accounts that are not yours, and give us reasonable time to fix an issue before disclosing it.

Data incidents

If a breach affects your personal data we will notify you without undue delay and within 48 hours of becoming aware, with what you need to meet your own 72-hour obligation to the ICO.

Need something not covered here?

Send us the questionnaire. We would rather answer it properly than have you guess from a marketing page.