Skip to main content

Trust & security

Ground data is evidence. Treat it like evidence.

A geotechnical record is relied on for design decisions and defended years later. This page states what G& does today to keep that record confidential, recoverable and provable — including what is not yet certified. Every item is labelled: in place, a contractual target, available on request, or not certified.

Hosting model
Managed cloud, single-tenant database per customer estate
Encryption
TLS 1.2+ in transit · AES-256 at rest
Audit log
Append-only, every create / edit / approve / export
Certification
ISO 27001 aligned · not yet certified

Controls, stated plainly

Written for the person completing a security questionnaire. Figures specific to your deployment tier are confirmed in the agreement rather than advertised here.

TS-01In place

Data residency

Each customer estate is provisioned in one nominated hosting region and stays there; data is not replicated to other regions for convenience. Region is fixed at provisioning and recorded in the agreement. Additional regions for jurisdictions with in-country data requirements are assessed per contract.

TS-02In place

Encryption

All traffic between clients, field devices and the platform runs over TLS 1.2 or higher. Data at rest — database, file attachments, field photographs, scanned log sheets and generated deliverables — is encrypted with AES-256 using managed keys. Credentials are stored as salted hashes, never in recoverable form.

TS-03Target

Backups and recovery

Continuous point-in-time recovery over a rolling window, plus daily snapshots retained on a defined schedule. Recovery-point objective (RPO) and recovery-time objective (RTO) are stated as service targets in the agreement rather than open-ended promises, and restore drills are run against a non-production copy. Ask for the current target figures for your deployment tier.

TS-04In place

Audit logging

Every record creation, edit, validation override, approval, signature and export is written to an append-only audit log with actor, timestamp, previous value and governing standard version. Log entries cannot be edited or deleted by platform users, including administrators. Retention period is set per customer and stated in the agreement.

TS-05In place

Access model

Role-based access at project and area level: field, laboratory, engineering, approver and read-only viewer. Approval and export rights are separated from data-entry rights so no single account can enter and certify the same value. Access is enforced server-side by row-level policies, not by hiding controls in the interface.

TS-06In place

Authentication

Email and password with breach-list screening, plus Google sign-in. Enterprise SAML single sign-on and directory-driven provisioning are available on request for organisations that require them. Sessions expire and can be revoked centrally.

TS-07In place

Data ownership and exit

Your data remains yours. A full export in AGS 4.1 plus Excel is available at any time, at no charge, without a support request or exit fee. On termination the estate is exported and then deleted on a defined schedule.

TS-08In place

Environment separation

Production, staging and development are separate environments. Production data is not copied into development; test datasets are anonymised. Administrative access to production is limited to named personnel and logged.

Sub-processors

G& relies on a deliberately short list of processing categories. The named provider and contract terms for each category are supplied under NDA during procurement, and customers are notified before a category changes.

CategoryPurposeData in scope
Cloud hosting and managed databaseRuns the application, database, object storage and backupsAll customer data, within the nominated hosting region
Transactional email deliveryAccount, notification and approval-request emailsRecipient name and email address, message subject and body
AI inference providerHandwriting transcription of field sheets and the site assistantOnly content submitted to those features; not used to train third-party models

Certification status — no overclaiming

Certification claims are easy to make and easy to check. G& states its position exactly.

ISO/IEC 27001Not certified

G& is not ISO 27001 certified today. The platform's controls — access control, cryptography, logging and monitoring, backup, supplier management, change control — are built to align with the Annex A control set, and the control mapping is available for review under NDA. Any future certification will be published here with the certificate number and scope, not before.

SOC 2 Type IINot certified

No SOC 2 report has been issued. Where a tender requires third-party assurance, G& answers security questionnaires directly and will support a customer-led or independent assessment of the deployment.

AGS 4.1 data standardIn place

Not a security certification, but a governed conformance point: exports are validated against the AGS 4.1 dictionary before release, and the standard version that produced each value is stored with it.

Security questionnaires and disclosure

G& completes customer security questionnaires, supports data-processing agreements, and will walk a client IT or assurance team through the deployment architecture, the control mapping, and the audit-log model. Suspected vulnerabilities are handled seriously: report through the contact form and expect an acknowledgement, an assessment, and a remediation position.

Security pack
Control mapping, architecture note, DPA template
Questionnaire turnaround
Completed within the tender window
Data export
AGS 4.1 and Excel, any time, no charge
Vulnerability reports
Acknowledged, assessed, remediation stated