Security and data
Plain answers to the questions a buyer's IT team asks — including the ones where the honest answer is 'not yet'.
Where your data lives
KonstanTrack runs on managed UK infrastructure (Azure, UK South region), so customer data stays in the UK. Traffic is encrypted with TLS, access is role-based, and a DPA is available on request.
The controls in place
| Hosting | Managed UK infrastructure — Azure, UK South region. Customer data stays in the UK. |
|---|---|
| Encryption | TLS for all traffic in transit; encryption at rest on the underlying managed storage. |
| Access | Role-based. People see what their role needs — PM, engineer, QA, viewer — not everything. |
| Separation | Each customer's data is scoped to their own tenant and enforced at the database layer, not just in the interface. |
| Audit trail | Key actions — approvals, stage sign-off, NCR closure, test records — are recorded with who and when. |
| Authentication | Secure password handling with token-based sessions. |
| Backups | Database and uploaded-file backups on a rolling retention window, held in the same UK region. Restore procedure documented. |
| Data protection | Operated under UK GDPR, with data minimisation, a defined retention approach and a DPA on request. |
| Export | Full export of your own data, on request, at any point. |
What we do not claim
Security pages usually list only what looks good. This is the other half, because you will find it out anyway and it is cheaper for both of us if you find it out now.
- No ISO 27001, SOC 2 or Cyber Essentials certification.
- No published third-party penetration-test report.
- No claim that using KonstanTrack makes an assembly compliant with any standard.
- No guarantee of uptime beyond what is agreed commercially.
Standards, and what software can and cannot do
KonstanTrack supports the documentation and workflow you already work to under BS EN IEC 61439 and BS 7671. It holds the released design, the BOM, inspection records and test results together against the job, so the evidence trail is structured and findable.
It does not certify assemblies, guarantee compliance, or replace design verification, routine verification or the judgement of the competent people carrying it out. The standard is the bar; the trail is how you show you cleared it.
Reporting a vulnerability
If you believe you have found a security issue, email [email protected] with enough detail to reproduce it. We will acknowledge within five working days. Please do not test against live customer data.
Common questions
Where is our data held?
On managed UK infrastructure (Azure, UK South region). Your data stays in the UK.
Do you hold ISO 27001 or Cyber Essentials?
No. We hold no security certification today and will not imply otherwise. What we can describe is the controls actually in place — encryption in transit and at rest, role-based access, a full audit trail on key actions, and a deliberately small attack surface.
Can we get a DPA?
Yes. A Data Processing Agreement is available on request as part of the commercial conversation.
Do we own our data, and can we get it out?
Yes. Your project data is yours, full export is available, and there is no lock-in culture. If you leave, you leave with your records.
Who inside KonstanTrack can see our data?
Access is role-based and limited to what is needed for support. Every tenant's data is separated, and key actions are recorded in an audit trail.
Related

Need this in a supplier questionnaire?
Send the questionnaire with your quote request and we will answer it directly, including the questions where the answer is no.
Request a quoteLast reviewed: . Written and maintained by the KonstanTrack team.
