Groundline

Security and privacy

Your acquisition targets are not our training data

A land intelligence platform holds a list of the properties you are about to bid on. That is among the most commercially sensitive data a developer has.

Commitments

  • We do not train models on customer data, and we do not sell it
  • You own your queries, uploads, projects, assumptions and generated reports
  • Configurable retention, with permanent deletion that actually deletes
  • Confidential project mode disables share links and strips project identifiers from operational logs
  • Enterprise data processing agreement with a published subprocessor list and change notice
  • Encryption in transit and at rest; per-organisation isolation enforced in the data layer, not in route handlers
  • Administrative access to customer data is logged to an append-only audit sink and reviewed
  • Setting the Copilot provider to deterministic makes zero outbound AI requests — the full workflow runs with no model provider involved

Programme

AreaControlStatus at launch
AccessRole-based access control, least privilege, MFARBAC and MFA on every plan; single sign-on available on Enterprise
TenancyOrganisation scoping enforced in the persistence layer; cross-tenant access raises rather than returns emptyAt launch, with automated tenant-isolation tests
EncryptionTLS 1.2+ in transit, AES-256 at rest, managed key rotationAt launch
SecretsManaged secret store, no secrets in source or imagesAt launch
AuditAppend-only audit log of authentication, authorisation, data access and administrative actionAt launch
Vulnerability managementDependency and container scanning in CI, patch service levels by severityAt launch
Penetration testingAnnual third-party test, remediation tracked to closureBefore first municipal contract
SOC 2 Type IIFull control set with a named auditorTarget: month 18
Incident responseDocumented plan, named roles, customer notification commitmentsAt launch
Backup and recoveryPoint-in-time recovery, restore tested quarterlyAt launch
A dependency you cannot audit is a risk you cannot manageThe Groundline analysis core, report generator and API run with zero third-party runtime dependencies. Report generation handles the most sensitive data in the product; giving it a large dependency tree would put the highest-value asset behind the widest attack surface.