Trust centre
Security controls
VariationDesk is designed for commercially sensitive project records. Security controls are built into organisation access, evidence storage, mobile use, finance hand-off and internal support — not added only at the edge of the product.
Organisation isolation
Workspace APIs and database policies scope customer records to the signed-in organisation. Release checks include cross-organisation access tests for core records, evidence and finance routes.
Role and permission controls
Field, office and management access is permission-controlled so users do not automatically receive access to every commercial or administrative action.
Private evidence storage
Photos, voice recordings, signatures, support attachments and generated records use private storage. Access is authenticated or provided through short-lived signed links where a controlled external flow is required.
Secure mobile storage
The mobile app keeps authentication material in platform-secure storage, protects local iOS files while the device is locked and limits lock-screen notification detail.
Activity and audit history
Material actions such as approvals, sign-off, project reassignment, exports, support actions and selected security events are recorded for accountability.
Controlled finance integrations
Accounting connections and exports require authorised workspace access. Automated exports use guarded jobs with retry, stale-job recovery and duplicate-success protection.
Release security gates
VariationDesk maintains automated checks for application boundaries, mobile security, responsive behaviour, session handling and release readiness before production changes are promoted.
Restricted internal access
Internal operations and support surfaces are separated from customer routes and require privileged staff authentication and access controls.
Operating practices
Security also depends on how the service is operated.
Backups and recovery
Managed database and storage services are used with recovery procedures reviewed as the platform grows. Recovery testing is treated as an operational release requirement rather than assumed from provider availability.
Diagnostics
Privacy-minimised reliability diagnostics can record app/build version, platform, screen/action references and redacted errors. They are designed not to collect evidence photos, voice recordings or transcripts, signatures, passwords or full variation payloads.
Privacy and retention
VariationDesk maintains privacy-request, retention and processing records so customer and diagnostic data can be handled consistently.
Security reports
Customers or researchers who believe they have found a security issue can contact support@variationdesk.co.uk. Please avoid including live customer evidence or credentials in the initial report.
This page describes current controls in plain English and is not a certification claim. Enterprise customers can request more detailed security and data-processing information during procurement.