Security & Governance
CapexIQ is designed for sensitive capital-project information. Security, tenant boundaries, source authority, auditability, and controlled decision workflows are treated as platform requirements rather than marketing add-ons.
Public Security Overview — September 4, 2026
This page provides a high-level description of CapexIQ security and governance principles. Exact infrastructure controls, certifications, service levels, data-residency commitments, and customer-specific security configurations should be confirmed through the applicable security review and contractual documentation.
1. Data Protection
CapexIQ is designed to protect customer project documents, estimates, cost knowledge, market information, and business data throughout processing and storage.
- Encrypted transport and protected storage using industry-standard security mechanisms
- Controlled access to application and administrative functions
- Governed handling of uploaded documents, generated outputs, and external-source snapshots
- Security-sensitive configuration and secrets kept outside normal user-facing workflows
2. Tenant & Knowledge Isolation
Customer data and knowledge are governed within organizational boundaries.
- Organization-scoped project and user access
- Customer-specific corporate knowledge isolated from CapexIQ-owned knowledge and other customers
- Project-specific knowledge remains project-scoped unless an explicit governed promotion occurs
- RFI, vendor, external-estimate, and market information does not silently become enterprise knowledge
3. Identity, Roles & Access
CapexIQ uses role and permission boundaries to restrict actions to authorized users.
- Role-based access to projects, documents, estimates, knowledge, exports, and administration
- Controlled user provisioning and deprovisioning workflows
- Administrative actions separated from ordinary project workflows
- Customer-specific identity and access configurations can be addressed during deployment planning where supported
4. Auditability & Revision Governance
Governed capital decisions require reconstructable history.
- Material workflow actions and governed decisions are retained with traceability
- Historical accepted document and estimate revisions remain immutable
- Market response normalization and disposition preserve source evidence and rationale
- External-source mappings, validation, and accepted project use retain provenance
5. External Integrations
Connected external systems are treated as separate authorities rather than uncontrolled extensions of the CapexIQ database.
- Organization-scoped connector configuration
- Least-privilege access is the design target for customer-authorized connections
- Read-only integration is preferred before write-back unless a governed business requirement justifies otherwise
- Bidirectional actions require explicit authorization and should not silently overwrite source-system information
- Synchronization history and source provenance are retained where applicable
6. Deterministic Governance of AI-Assisted Workflows
AI may assist with interpretation, extraction, proposed mappings, or recommendations. AI does not silently become authoritative for final estimating, pricing, risk, benchmarking, disposition, or enterprise-knowledge decisions.
7. Security Assurance & Customer Review
Security evidence should match the deployed environment and applicable customer agreement. Where customers require detailed questionnaires, architecture review, data-residency discussion, contractual security commitments, or available compliance evidence, CapexIQ will address those requirements through the enterprise evaluation and contracting process.
No feature-gated security marketing: CapexIQ's commercial model is based primarily on organizational capacity rather than withholding the platform's core capabilities by tier. Deployment-specific security configurations may still depend on technical environment, customer infrastructure, and agreed implementation scope.
8. Security Contact
For security inquiries or to request current security documentation:
CapexIQ Technologies Inc.
Email: admin@capexiq.io
Subject Line: Security Inquiry
Request Walkthrough