Skip to main content
CONHUBAIPROJECT INTELLIGENCE
SECURITY + DATA GOVERNANCE

Current controls, clear boundaries, and no invented certifications.

This center explains what CONHUBAI does today, what remains device-local or request-only, and which organization controls are still planned. Pilot security reviews use the same distinction.

AVAILABLE TODAY

Implemented controls and data boundaries

These statements describe current application behavior. Provider and contract evidence can be reviewed during a scoped pilot.

ACTIVE

Authentication

Individual email-and-password accounts use Supabase authentication. Password recovery uses expiring, single-use verification challenges.

ACTIVE

Private preview

Protected product routes can require a signed, expiring HTTP-only preview cookie. The public RFI example does not unlock product access.

ACTIVE

Administrator access

Administrative authorization is tied to immutable user identifiers rather than email-address matching.

ACTIVE

Transport and browser protections

HTTPS, HSTS, content-security policy, request-origin validation, restricted framing, MIME protection, and bounded request bodies are configured.

ACTIVE

Account data

Signed-in Adviser conversations and controlled project context can be stored with the account in Supabase. Billing and product-event records are server controlled.

ACTIVE

Device drafts

Preconstruction and certain preview workspace drafts remain on the current device. They are labeled as device data and can be exported or cleared by the user.

ACTIVE

Request-only files

Uploaded working files are processed for the active request and are not presented as a permanent account document library. File type, size, and unsafe Office archive content are checked.

ACTIVE

AI processing

CONHUBAI uses external AI API providers to process submitted prompts and authorized files. CONHUBAI does not use customer project content to train its own models. Provider processing terms are reviewed during a pilot.

ACTIVE

Billing control

Paid access is granted only after signed provider events. Checkout, renewal choice, cancellation, receipts, refunds, disputes, and webhook idempotency are implemented.

ACTIVE

Export and deletion

Users can download generated records and export supported workspace data. Device drafts can be cleared locally; account-data deletion requests are handled through Support.

DATA LIFECYCLE

Know what is saved before you begin.

Account record

Signed-in conversations and controlled project context may be saved to the account.

Account access · server stored
Device draft

Preconstruction and selected preview workspace drafts stay in the browser until export or clear.

Current device · user controlled
Request-only file

Selected files are used for the active request and are not presented as a permanent document repository.

Transient processing · provider involvement
System of record

Procore, Autodesk, SharePoint, P6, approved document control, and company systems remain authoritative.

External system · not replaced
PLANNED · NOT COMPLETE

Organization-control roadmap

These items are disclosed for planning. They must not be treated as available controls in a proposal or security questionnaire.

PLANNED

MFA and SSO

Not currently offered as an organization control. SAML SSO and enforced MFA remain planned and require security validation.

PLANNED

Project and tenant roles

Individual accounts exist today. Separate-user organization roles, project permissions, invitations, and managed seats are not represented as complete.

PLANNED

Central audit log

Billing and selected product events are recorded, but a customer-facing organization audit-log center is not yet available.

PLANNED

Formal certification

CONHUBAI does not currently claim SOC 2, ISO 27001, or another independent security certification. Certification planning follows pilot requirements.

PLANNED

Private deployment options

Dedicated tenant, private-cloud, and customer-managed model deployment are not currently advertised as available.

SECURITY REVIEW

Bring the actual requirements.

Share authentication, retention, residency, subcontractor, incident-response, export, and certification requirements before a pilot is scoped.

Start a pilot discussionContact Support