Security & access

Claim data is commercially sensitive. It's treated that way.

Notices, particulars, and determinations carry real financial exposure. ContractIQ separates who can see, who can edit, and who can approve — and records every one of those actions.

Role-based access

Permissions that match your commercial structure.

Four roles, each scoped to what that person actually needs — visibility without edit rights, operational access without admin rights.

DirectorFull visibility across the portfolio. No data edit rights.
Commercial DirectorCross-project oversight. Approve, reject, or escalate any claim.
Quantity SurveyorDay-to-day operational user. Logs events, drafts notices, files evidence.
System AdminUser and project configuration. No access to live claim data.
Platform security

The controls behind the roles.

Complete audit trail

Every action logged with user, timestamp, and prior value. When a claim escalates to dispute, the record of who knew what and when already exists.

Encrypted in transit and at rest

TLS for all traffic, encrypted storage for documents and claim data on managed cloud infrastructure.

UK data residency

Data hosted in the UK region, appropriate for UK contracting entities and their commercial data.

Email-invite provisioning

Users are invited by email and provisioned in minutes — no IT project, no on-premise install, and access revoked instantly on leaving.

Project-scoped visibility

Users see only the projects they're assigned to. Portfolio-wide visibility is a deliberate, separately granted permission.

Document version control

Evidence is versioned per claim, so superseded submissions remain retrievable rather than overwritten.

TLS 1.3Encrypted at restUK regionRole-based accessFull audit log

Need to run this past your IT or compliance team?

Talk to us