Security and confidentiality
Confidential by default, not by request.
The documents behind a private project are sensitive before anything else. The handling of them is built around that.
NDA-first engagement
Every relationship begins with a non-disclosure agreement, before any project document is exchanged. Terms confirm that whoever uploads a document is authorized to do so, including documents originally produced by a consultant, contractor or other third party.
Tenant and project isolation
Each client’s records are isolated by tenant and by project. A reviewer or an automated step working on one engagement has no path to another client’s documents.
An immutable evidence chain
Original documents are hashed and versioned on arrival and are never edited afterwards. Every finding cites the exact document, version and page it rests on, so the chain from finding back to source is always intact.
Human validation
A material finding is not client-facing until a qualified reviewer has checked it. The record shows who validated it and when, alongside the finding itself.
Encryption and access control
Documents are encrypted in transit. At rest, application-level encryption of the document bytes and extracted page text is not yet in place — protection there comes from the operating environment and from access control — so until that work is closed, each engagement is run on an isolated, tightly access-controlled environment rather than a shared one. Access is limited to the people working on your engagement, logged, and subject to periodic review.
Retention and deletion
Retention periods are agreed with you and are configurable per engagement. Secure deletion is available once an engagement and its agreed retention period have concluded.
Audit trail
Every document version, finding, reviewer decision and export is logged, so the full history of an engagement can be reconstructed on request.
Controlled use of automation
Where automated tools assist tracing and drafting, the provider and method in use are recorded internally, source content sent to any tool is minimized, and credentials are isolated per engagement. Automation output is never treated as final on its own.
What CostBleed is, and is not
CostBleed provides cost assurance, evidence intelligence, structured decision support and a review workflow. It does not provide legal advice, formal contractual certification, adjudication or arbitration, or debt collection, and it does not replace your appointed quantity surveyor, contract administrator or solicitor.
A finding that a cost is not currently supported is a statement about the documents reviewed, not a conclusion about anyone’s intent. Where a package requires legal, contractual or professional judgment beyond that, we say so and point you to the right advisor.
Questions before you send anything
If your firm has a specific confidentiality or data-handling requirement, raise it before the NDA is signed and we will confirm in writing how it is met.
Request a confidential scan