SaferSite

Trust & Security

RAMS documents carry the details of how work gets done on your sites — methods, sequences, the people involved. We treat them accordingly. Here is exactly how your data is held, who can reach it, and what we do with it.

Security

Your documents live on UK infrastructure, encrypted in transit and at rest, isolated from every other organisation on the platform, with every access recorded.

Compliance

Built to ISO 27001 standards and operated under UK GDPR. A complete audit trail of who did what and when, retained for seven years to match construction record-keeping requirements.

Improvement

Every correction your reviewers make raises the standard of every review that follows. That feedback loop is the point of the platform — fewer hazards missed, on every site.

How we protect your data

Where is our data stored?

In the United Kingdom. The platform runs on Microsoft Azure in the UK South (London) region — application, database, and document storage alike. SaferSite is a UK company currently serving UK customers; as we open in other regions our intention is to host customer data within the customer's own region.

Who can see our documents?

Only authorised users within your own organisation, and the subcontractors you invite to a specific site. Your data is separated from every other organisation at the database level, and every query is scoped to your organisation and site. No other customer can see your content — not your documents, not your findings, not your site rules.

Do you use our documents to improve the platform?

Yes, and we think that is the most valuable thing about it. When your reviewers correct a finding, reject one, or add one we missed, that judgement is retained along with the document it relates to and used to improve our review models. Expert corrections made on your sites raise the standard of every review that follows. Improvement shows up only in the general capability of the models — your documents are never sold, never shared with another customer, and never shown to one. If you would rather your organisation was excluded, we can switch it off for you.

Are our documents used to train anyone else's systems?

No. Your documents are never used to train third-party systems. The specialist provider that runs our review models does not train on customer data, and we do not sell or license your content to anyone.

How is access controlled?

Role-based, from director down to viewer. Each role sees only what it needs — billing is restricted to a single administrator role, site and team management is closed to subcontractors and viewers, and reviewers are scoped to their own sites. Sessions are held in a secure, httpOnly cookie and passwords are hashed.

Do you hold security certifications?

The platform is built to ISO 27001 standards — access control, audit logging, input validation, environment isolation and change management are all implemented against those controls. We are not currently certified against ISO 27001 or SOC 2, and we would rather tell you that plainly than imply otherwise. If certification is a procurement requirement for you, talk to us about timelines.

What happens to our data if we leave?

You have 30 days from cancellation to export everything. After that we delete your account data, RAMS documents, and site data. Audit trail records and financial records are kept for seven years, as construction health and safety record-keeping and HMRC rules require.

Need the detail?

The full legal position is set out in our Privacy Policy and Terms of Service. For security questionnaires, due diligence, or anything not answered here, contact steve@safersite.app.