Trust centre

Security controls

VariationDesk is designed for commercially sensitive project records. The controls below explain how customer workspaces, evidence, mobile access, accounting connections and support access are protected in day-to-day use.

Private evidenceRole-based accessAudit historyIsolation testing

Organisation isolation

Each customer workspace is separated from other organisations. Access to projects, variations, evidence and finance actions is checked against the signed-in organisation and the user's authorised role.

Roles, access groups and permissions

Owners and managers can control what field and office users are allowed to see and do, including project access and higher-risk commercial or administrative actions.

Private evidence storage

Photos, files, signatures, support attachments and generated records are kept in private storage. Controlled external flows use authenticated or time-limited access rather than public file links.

Secure mobile use

The mobile app uses platform-secure storage for authentication material, protects local iOS files while the device is locked and limits sensitive detail shown in lock-screen notifications.

Activity and audit history

Important actions such as approvals, sign-off, pricing changes, project reassignment, exports and selected support or security events are recorded so the commercial history can be reviewed.

Controlled accounting connections

Accounting connections and exports require authorised workspace access. Successful finance handoffs are protected against accidental duplicate processing and remain visible in the variation history.

Security testing before release

Automated checks cover cross-organisation access, role escalation, session handling, mobile boundaries, commercial controls and other release-critical security behaviour before changes are promoted.

Restricted VariationDesk staff access

Internal operations and support tools are separate from customer workspace routes and require privileged staff authentication. Support access is controlled rather than providing general access to every customer record.

Operating practices

Security also depends on how the service is operated.

Backups and recovery

VariationDesk uses managed database and storage services and maintains recovery procedures as the platform grows. Recovery is treated as an operational responsibility rather than assumed from provider availability alone.

Privacy-minimised diagnostics

Reliability diagnostics can include app or build version, platform, screen or action references and redacted errors. They are designed not to collect evidence photos, voice recordings or transcripts, signatures, passwords or complete variation payloads.

Privacy and retention

VariationDesk maintains privacy-request, retention and processing records so customer and diagnostic data can be handled consistently.

Reporting a security concern

If you believe you have found a security issue, contact support@variationdesk.co.uk. Please do not include live customer evidence, passwords or credentials in the first message.

This page describes current controls in plain English and is not a certification claim. Enterprise customers can request more detailed security, data-processing and deployment information during procurement.