Trust Center
Security and compliance are core to every preconstruction workflow you run in Consight. We protect access to your bid documents, isolate every organization’s data, and keep AI processing tightly scoped.
This page summarizes our current controls, sub-processors, and data residency, along with answers to the security questions we’re asked most often during vendor reviews.
Data residency
All core infrastructure in the United States
Zero Data Retention
External AI providers don’t retain prompts
No model training
Customer data is never used to train providers
SSO and MFA
OIDC and SAML via Clerk, role-based access
Security and data handling
AI data flow and boundaries
Uploaded plans, specs, and bid forms are processed inside Consight and routed to AI providers only for the request at hand. If you need manual control over data handling rather than confirmation of the controls we already enforce automatically, tell us and we’ll scope that with your team.
Training data usage
Customer data is not retrievable or exposed through model outputs, and external AI providers do not train on customer data due to Zero Data Retention configurations. Internal model improvements use sanitized datasets with PII and identifying metadata removed, handled under controlled access and not attributable to any individual customer.
Tenant isolation assurance
Tenant isolation is enforced through a logical multi-tenant architecture with organization-scoped authentication, authorization checks, and tenant-aware data access controls. All requests are validated against tenant context at the API, database, and object levels. AI processing runs in isolated per-request execution environments with strict access enforcement via identity tokens and role-based permissions.
Vector and embedding storage
Vector embeddings are generated from uploaded documents to support search and platform functionality. These embeddings are non-reversible numeric representations, scoped to the originating organization, and protected by strict access controls. They follow the same lifecycle as primary data and can be deleted on request, including removal from backups within standard retention windows.
Audit logging
Audit logging is not currently supported. We are open to aligning with customer requirements and can discuss implementing appropriate audit logging capabilities if needed.
Identity controls
Authentication is managed through Clerk, supporting SSO via OIDC and SAML. MFA is supported through the identity provider and can be enforced based on organizational configuration. Authorization is role-based, with permissions enforced at the organization and object levels.
Data residency
All core infrastructure operates within the United States. The primary application and database are hosted in Oregon (us-west-2), with backups and failover in Virginia (us-east-1) and Ohio (us-east-2). AI processing is handled through external providers via OpenRouter and may occur across multiple geographic regions.
Sub-processors
AWS
Infrastructure and storage
Vercel
Application hosting
Neon
Database services
OpenRouter
AI routing layer
OpenAI
AI provider
Google Gemini
AI provider
Clerk
Authentication and identity
Stripe
Billing and payments
Procore
Optional third-party integration
BuildingConnected
Optional third-party integration
Need something more specific?
For security reviews, DPAs, or questionnaire support, reach our team at security@consight.ai and we’ll respond with the detail your process requires.