Security & Data Protection
We understand that construction contracts contain commercially sensitive information — pricing, insurance details, liquidated damages clauses, and trade secrets. Protecting your data is not an afterthought; it is foundational to everything we build.
Bank-Grade Encryption
Every contract you upload is encrypted at rest using AES-256 encryption — the same standard used by banks and government agencies. All data transmitted between your browser and our servers is protected with TLS 1.2+ encryption, ensuring your documents cannot be intercepted in transit.
Strict Access Control
Your company operates in a complete silo. No other company, user, or administrator can see your contracts, analysis results, or payment claims. Access is controlled through role-based permissions — only your Company Admin can add team members, and each user sees only the contracts assigned to their company. When you share a contract with a lawyer for review, they receive a secure, time-limited link.
Authentication & Session Security
All passwords are hashed using bcrypt before storage — we never store or have access to your plaintext password. User sessions are secured with signed, encrypted tokens that expire after a period of inactivity. Every API request is authenticated and authorised, ensuring only verified users with the correct role and company membership can access data.
We Never Train AI on Your Data
This is a firm, non-negotiable policy. Your contracts, clauses, pricing, and analysis results are never used to train, fine-tune, or improve any AI model — ours or anyone else's. When our AI analyses your contract, the content is processed in a stateless session and is not retained after the analysis is complete. Your data exists solely for your benefit.
Secure Cloud Infrastructure
ContractGuard runs on enterprise-grade cloud infrastructure with automatic backups, redundancy, and monitoring. Our systems are designed for high availability and are regularly updated with the latest security patches. File storage uses dedicated, access-controlled cloud storage buckets with server-side encryption enabled by default.
Data Breach Response Plan
We have a formal incident response process in place for handling any suspected or confirmed data breach. In the unlikely event of a security incident:
- 1.Contain & Investigate: We immediately isolate the affected systems to prevent further exposure and begin a thorough investigation to determine the scope, nature, and cause of the incident.
- 2.Notify Affected Users: In accordance with the NZ Privacy Act 2020, we will notify all affected users and the Office of the Privacy Commissioner as soon as reasonably practicable if the breach is likely to cause serious harm. Our target is notification within 72 hours of confirming a notifiable breach.
- 3.Transparent Communication: Notifications will clearly describe what happened, what data was involved, what we are doing about it, and what steps you can take to protect yourself (such as changing your password).
- 4.Remediate & Prevent: We fix the root cause, strengthen controls to prevent recurrence, and document lessons learned. Any changes to our security practices as a result will be communicated to affected parties.
How We Keep Your Information Safe
Security is built into every layer of ContractGuard NZ. Here is a summary of the measures we have in place:
Network & Transport
All connections are encrypted with TLS 1.2+. HTTPS is enforced on all endpoints — no plaintext HTTP traffic is accepted.
Storage & Encryption
Files are stored in access-controlled cloud storage with AES-256 server-side encryption. Database records are encrypted at rest. Backups are automated and encrypted.
Application Security
Role-based access control enforces company-level data isolation. API routes validate authentication and authorisation on every request. File sharing uses time-limited, password-protected links.
Monitoring & Updates
Infrastructure is continuously monitored for anomalies. Security patches are applied promptly. Systems are regularly reviewed and hardened against emerging threats.
Data Minimisation
We collect only the personal information needed to provide the service (name, email, job title, company). We do not collect financial information, government IDs, or unnecessary personal data.
Data Handling & Retention
You own your data. We store your contracts and analysis results only for as long as your account is active and you choose to retain them. You can delete individual contracts at any time, which removes the files from our storage. If you close your account, all associated data is permanently deleted within 30 days.
Responsible Disclosure
If you believe you have found a security vulnerability in ContractGuard NZ, we encourage you to report it to us responsibly. Please email [email protected] with details of the issue. We will acknowledge your report within 2 business days and work with you to understand and resolve it promptly. We will not take legal action against security researchers who act in good faith.