Security & trust

Your tender documents never leave your control.

Preckon ingests some of the most sensitive documents a contractor holds — live bids, contracts, full design sets. Security isn't a page of fine print here; it's built into how every document is handled, from upload to audit.

Encrypted in transit & at rest Isolated per tenant Not used to train shared models SOC 2 in progress
The trust path

What protects a document at every step.

Follow a drawing set from the moment it's uploaded. Each stage adds a control — encryption, isolation, independence, review, audit — before anything moves on.

STEP 01
TLS 1.2+

Upload

Documents are encrypted in transit the moment they leave your machine.

STEP 02
RLS · ENCRYPTED AT REST

Tenant vault

Stored in your isolated tenant, separated at the database layer by row-level security.

STEP 03
PROVIDER-INDEPENDENT

Processing

The orchestrator routes tasks across providers, so no single vendor ever sees your whole project.

STEP 04
HUMAN-IN-THE-LOOP

Review

Your team confirms or corrects every output. Nothing is costed or issued automatically.

STEP 05
IMMUTABLE

Audit

Every action is logged — who, what, when — so any number can be proven end to end.

The pillars

Six commitments behind that path.

Encrypted end to end

TLS in transit and AES-256 at rest. Your documents are protected the moment they're uploaded and everywhere they sit.

Isolated per tenant

Row-level security separates every client at the database layer. One tenant's data is never visible to another.

Never used to train shared models

Your tenders and drawings are yours. Preckon does not use your documents to train models shared with anyone else.

Provider-independent by design

Work is routed across multiple AI providers, so no single vendor sees your whole project. Independence is a security posture, not just flexibility.

Immutable audit spine

Every action and change is recorded — who, what, when — so you can prove exactly how any number was produced.

Human in the loop

Nothing is costed or issued without a person confirming it. AI proposes; your team decides.

Data ownership

Your data is yours. Full stop.

You own every document you upload and every output Preckon produces. Export it whenever you want, and have it deleted on request. We don't sell it, we don't share it, and we don't train shared models on it.

Compliance & posture

Where we are, stated plainly.

We'd rather tell you exactly where things stand than imply a certificate we don't hold yet.

SOC 2
Type II underway; controls implemented, audit in progress. Report available under NDA when complete.
IN PROGRESS
Encryption
TLS 1.2+ in transit, AES-256 at rest.
LIVE
Access control
SSO and role-based access control (RBAC); least-privilege by default.
LIVE
Tenant isolation
Row-level security enforced at the database layer.
LIVE
Audit logging
Immutable, per-tenant record of every action and change.
LIVE
Data residency
Regional hosting options for enterprise agreements.
ENTERPRISE
Sub-processors
Provider-independent AI; documented sub-processor list available on request.
LIVE
Security questions

The ones your IT team will ask.

Do you train AI models on our data?
No. Your documents are not used to train models shared with other customers. Any learning from your corrections stays within your own tenant and improves results on your projects only.
Where is our data stored, and who can access it?
In your isolated tenant, encrypted at rest and separated by row-level security. Access is governed by SSO and role-based controls on a least-privilege basis, and every access is audit-logged. Regional residency options are available for enterprise agreements.
Which AI providers do you use?
Preckon is provider-independent. The orchestrator routes each task to the appropriate model, so no single vendor sees your whole project. A documented sub-processor list is available on request.
What happens to our data if we leave?
You can export your documents and outputs at any time, and request full deletion of your data. It's yours to take with you.

Bring your security team to the first call.

We'll walk your IT and procurement people through the controls, the sub-processor list, and the SOC 2 timeline.