SitePilot Security and Data Practices | SitePilot CPMS

Security and operational trust

SitePilot CPMS Security and Data Practices

SitePilot uses authenticated access, role-based application controls and HTTPS transport to protect access to construction project records. This page describes current controls at a practical level without claiming certifications that have not been independently verified.

01

Authenticated application access

SitePilot users access protected workspaces through authenticated sessions. Customer and operations areas use authorization controls so public visitors cannot open private application routes.

  • Authenticated sessions
  • Protected account routes
  • Authorization checks
  • No public project pages
02

Role-based permissions

Application permissions are assigned by role and responsibility. Construction teams can separate administrative, sales, project, site and finance access instead of sharing one spreadsheet or account password.

  • Role assignments
  • Responsibility-based access
  • Restricted finance visibility
  • Administrative controls
03

Tenant-scoped project data

Product records use company-scoped query filters and tenant checks. Tenant document storage is separated by company identifier, and protected APIs require tenant context before serving workspace data.

  • Company-scoped records
  • Fail-closed tenant filters
  • Tenant-aware APIs
  • Separated document paths
04

HTTPS and encrypted database connections

Production traffic is redirected to HTTPS and the application enables HSTS outside development. Configured SQL Server connections use encrypted transport.

  • HTTPS redirection
  • HSTS in production
  • Encrypted SQL connections
  • Protected transport
05

Audit and session controls

Authorised administrators can review application data-change audit records, login activity and access sessions. Session-management controls support revocation when access must be withdrawn.

  • Data-change audit trail
  • Login events
  • Session history
  • Session revocation
06

Backup and recovery commitments

The repository does not establish a public backup frequency, retention period, recovery objective or disaster-recovery SLA. These requirements must be confirmed in the applicable proposal or service agreement before purchase.

  • No unsupported frequency claim
  • Contractual confirmation
  • Recovery requirements
  • Hosting-specific terms
07

Onboarding and support

The product includes a first-login setup workflow and tenant provisioning checklist. Training and migration assistance are provided only as included in the selected plan or agreement scope.

  • Welcome setup workflow
  • Role setup
  • Scoped migration assistance
  • Email, phone and ticket support
08

Shared security responsibilities

Customers remain responsible for choosing authorised users, protecting credentials, reviewing access when roles change and avoiding sensitive information in unapproved channels.

  • Unique user access
  • Credential protection
  • Access reviews
  • Responsible data sharing
Frequently asked questions

Security FAQs

Is SitePilot access role-based?

Yes. SitePilot includes role and permission controls for authorised application users.

Does SitePilot use HTTPS?

Yes. Production requests are redirected to HTTPS and HSTS is enabled outside development.

Is SitePilot ISO or SOC certified?

No certification claim is made on this page. Request current security and contractual documentation from the SitePilot team.

How often is data backed up?

Backup frequency and retention should be confirmed for the hosting arrangement and service plan in the applicable agreement.

Who should I contact about a security concern?

Use the SitePilot contact or authenticated support channel and do not include passwords or payment credentials in the message.

SitePilot CPMS

See how SitePilot fits your construction workflow

Discuss your projects, users and operating process with the SitePilot team.

Book a demo