Trust centre
Security controls
VariationDesk is designed for commercially sensitive project records. The controls below explain how customer workspaces, evidence, mobile access, accounting connections and support access are protected in day-to-day use.
Organisation isolation
Each customer workspace is separated from other organisations. Access to projects, variations, evidence and finance actions is checked against the signed-in organisation and the user's authorised role.
Roles, access groups and permissions
Owners and managers can control what field and office users are allowed to see and do, including project access and higher-risk commercial or administrative actions.
Private evidence storage
Photos, files, signatures, support attachments and generated records are kept in private storage. Controlled external flows use authenticated or time-limited access rather than public file links.
Secure mobile use
The mobile app uses platform-secure storage for authentication material, protects local iOS files while the device is locked and limits sensitive detail shown in lock-screen notifications.
Activity and audit history
Important actions such as approvals, sign-off, pricing changes, project reassignment, exports and selected support or security events are recorded so the commercial history can be reviewed.
Controlled accounting connections
Accounting connections and exports require authorised workspace access. Successful finance handoffs are protected against accidental duplicate processing and remain visible in the variation history.
Security testing before release
Automated checks cover cross-organisation access, role escalation, session handling, mobile boundaries, commercial controls and other release-critical security behaviour before changes are promoted.
Restricted VariationDesk staff access
Internal operations and support tools are separate from customer workspace routes and require privileged staff authentication. Support access is controlled rather than providing general access to every customer record.
Operating practices
Security also depends on how the service is operated.
Backups and recovery
VariationDesk uses managed database and storage services and maintains recovery procedures as the platform grows. Recovery is treated as an operational responsibility rather than assumed from provider availability alone.
Privacy-minimised diagnostics
Reliability diagnostics can include app or build version, platform, screen or action references and redacted errors. They are designed not to collect evidence photos, voice recordings or transcripts, signatures, passwords or complete variation payloads.
Privacy and retention
VariationDesk maintains privacy-request, retention and processing records so customer and diagnostic data can be handled consistently.
Reporting a security concern
If you believe you have found a security issue, contact support@variationdesk.co.uk. Please do not include live customer evidence, passwords or credentials in the first message.
This page describes current controls in plain English and is not a certification claim. Enterprise customers can request more detailed security, data-processing and deployment information during procurement.