Security + Trust

Controls For Confidential Bid Materials

VectorMetrics is designed for confidential construction workflows: bid packages, estimates, addenda, review notes, source exports, and action queues stay tied to customer accounts and role-aware access.

NDA available Role scopes Audit logs No public model training

Buyer-Safe Summary

Enterprise reviews can start with an NDA, a limited pilot package, and a branch-scoped rollout before broader connector or API access is configured.

Current Controls

Access Control

  • Authenticated account access for workspace features
  • Role-aware permissions for HQ, regional, and local workflows
  • Location scope support for branch-limited views
  • Owner/admin tooling for account and role setup

Auditability

  • Audit logs for account, integration, upload, and workflow events
  • Configurable audit log retention
  • Reviewable source sync health and failure states
  • Dead-letter handling for failed connector events

Infrastructure Readiness

  • PostgreSQL-ready application storage
  • Redis/RQ-backed async worker path for heavier processing
  • Background connector sync scheduler
  • Object-storage path for uploaded/generated files

Data Handling

  • Customer bid materials treated as confidential documents
  • Customer packages are not used to train public foundation models
  • Data minimization and pseudonymization settings available
  • File size, malware scan, and encryption settings available by environment

Enterprise Review Checklist

Before Data Access

  • NDA or pilot agreement as needed
  • Named business owner and technical owner
  • Allowed file types and retention expectations

Before Connector Setup

  • Confirm export/API path and update cadence
  • Confirm token handling and source ownership
  • Map branch, project, bid, estimator, and outcome fields

Before Expansion

  • Review pilot findings and adoption
  • Confirm role scopes by branch or region
  • Agree on executive reporting cadence