Trust Center

Security and data handling at Consight

Security and data handling at Consight

Security and compliance are core to every preconstruction workflow you run in Consight. We protect access to your bid documents, isolate every organization’s data, and keep AI processing tightly scoped.

This page summarizes our current controls, sub-processors, and data residency, along with answers to the security questions we’re asked most often during vendor reviews.

Consight

Data residency

All core infrastructure in the United States

Zero Data Retention

External AI providers don’t retain prompts

No model training

Customer data is never used to train providers

SSO and MFA

OIDC and SAML via Clerk, role-based access

Security and data handling

AI data flow and boundaries

Uploaded plans, specs, and bid forms are processed inside Consight and routed to AI providers only for the request at hand. If you need manual control over data handling rather than confirmation of the controls we already enforce automatically, tell us and we’ll scope that with your team.

Training data usage

Customer data is not retrievable or exposed through model outputs, and external AI providers do not train on customer data due to Zero Data Retention configurations. Internal model improvements use sanitized datasets with PII and identifying metadata removed, handled under controlled access and not attributable to any individual customer.

Tenant isolation assurance

Tenant isolation is enforced through a logical multi-tenant architecture with organization-scoped authentication, authorization checks, and tenant-aware data access controls. All requests are validated against tenant context at the API, database, and object levels. AI processing runs in isolated per-request execution environments with strict access enforcement via identity tokens and role-based permissions.

Vector and embedding storage

Vector embeddings are generated from uploaded documents to support search and platform functionality. These embeddings are non-reversible numeric representations, scoped to the originating organization, and protected by strict access controls. They follow the same lifecycle as primary data and can be deleted on request, including removal from backups within standard retention windows.

Audit logging

Audit logging is not currently supported. We are open to aligning with customer requirements and can discuss implementing appropriate audit logging capabilities if needed.

Identity controls

Authentication is managed through Clerk, supporting SSO via OIDC and SAML. MFA is supported through the identity provider and can be enforced based on organizational configuration. Authorization is role-based, with permissions enforced at the organization and object levels.

Data residency

All core infrastructure operates within the United States. The primary application and database are hosted in Oregon (us-west-2), with backups and failover in Virginia (us-east-1) and Ohio (us-east-2). AI processing is handled through external providers via OpenRouter and may occur across multiple geographic regions.

Sub-processors

AWS

Infrastructure and storage

Vercel

Application hosting

Neon

Database services

OpenRouter

AI routing layer

OpenAI

AI provider

Google Gemini

AI provider

Clerk

Authentication and identity

Stripe

Billing and payments

Procore

Optional third-party integration

BuildingConnected

Optional third-party integration

Need something more specific?

For security reviews, DPAs, or questionnaire support, reach our team at security@consight.ai and we’ll respond with the detail your process requires.