Skip to main content
SiteLive logoSiteLive

Trust & data security

Your site data, kept safe — and always yours.

The questions a serious builder asks before rolling software across every site: where data lives, how it's protected, who can see it, and what happens when you leave. Here are the straight answers.

How your data is protected

SiteLive runs on enterprise-grade cloud infrastructure that is independently certified to SOC 2 Type II and ISO 27001. Your data is encrypted in transit and at rest, with automated backups so nothing is lost.

  • Hosted on SOC 2 Type II and ISO 27001 certified infrastructure
  • Encryption in transit (TLS) and at rest
  • Managed cloud hosting with automated, regular backups
  • Each site and organisation is isolated at the database level

Access & accountability

People only see the sites they're on. Roles control what each person can do, and every meaningful change is written to an immutable activity trail.

  • Role-based access — admin, editor and view permissions
  • Per-site staff scoping; invited subbies see only what they're given
  • Full audit trail of who changed what, and when

Sign-in & identity

Use email and password or Google out of the box. Enterprises can connect their own identity provider with SAML single sign-on.

  • Email/password and Google sign-in included
  • SAML SSO available for enterprise rollouts (Okta, Entra ID, OneLogin)
  • Leaked-password protection on sign-up and password changes

Data ownership & exit

You own your data — we never sell it and never use it to train third-party AI. You can export it for free at any time while your account is active.

  • Free self-serve export, any time, while active
  • Downgrade never deletes files — over-quota sites go read-only, not erased
  • Construction records are kept; we never auto-delete for being over a limit

Infrastructure you can verify

Built on infrastructure that is already audited.

We do not self-host. SiteLive runs on managed cloud providers that publish their own compliance reports — so the security of the underlying platform is independently verified, not just promised.

SOC 2 Type II

Our hosting provider maintains an active SOC 2 Type II attestation covering security, availability, and confidentiality.

ISO 27001

The same infrastructure is certified to ISO 27001, the international standard for information security management.

Australian Privacy Principles

We are structured to comply with the Australian Privacy Act and the 13 APPs. Australian Consumer Law applies and is non-excludable.

GDPR-ready

Data export, right to deletion, and breach notification processes are built in for any UK or European users on your sites.

Running your own vendor review? We can share our sub-processor list and host security documentation under NDA. Request it.

Single sign-on

Sign in with the identity you already trust.

Everyone starts with email/password or Google out of the box. For larger rollouts, connect your own identity provider with SAML single sign-on — so access follows your existing joiner/leaver process, not a separate password list.

  • SAML 2.0 SSO for enterprise rollouts (Okta, Microsoft Entra ID, OneLogin)
  • Email/password and Google sign-in included on every plan
  • Central control — provisioning and de-provisioning through your IdP
  • Leaked-password protection on sign-up and password changes

AI you can trust

The AI works for you — on your data, and only your data.

SiteLive's AI reads the live bookings, dockets, diaries and records you already capture to answer questions and draft reports. It never guesses on your behalf when the facts aren't there, and it never learns from your data to help anyone else.

Grounded in your records

Answers and reports are built from your own live data — not the open internet — so what you read reflects what's actually on your site.

Never trains third-party models

Your data is never sold and never used to train external AI. It stays yours, used only to run SiteLive for you.

Traceable & reviewable

AI output is logged. Every generated report is attributable — you can see when it was produced and check it against the source.

Always your call

AI drafts and surfaces; people decide. Docket reads and reports are presented for you to confirm before they count.

Price-lock promise

The price you start on is the price you can plan on.

Your rate is locked for 12 months from the day you subscribe. If it ever changes after that, the change will be small — only ever to cover hosting and storage — and we'll tell you well in advance. No surprise hikes, ever.

  • Flat per-site pricing, the same across AUD, GBP, USD and EUR
  • Rate locked for 12 months from your subscription date
  • Any later change is small and communicated well ahead of time
  • Invited subbies confirm bookings on your sites for free
  • 7 days free on your first site — cancel before day 7 and pay nothing

Run like a company that's here to stay

We keep our own house in order — and keep the receipts.

Behind the product we keep dated, internal governance records — the same controls a SOC 2 or ISO 27001 assessor looks for. Not because we have to yet, but because the business you rely on should be run properly from day one.

Access reviews

We review who can reach systems on a regular cadence and record it — so access stays tight as the team changes.

Vendor register

Every sub-processor and tool we rely on is tracked, with its own security posture noted and reviewed.

Disaster-recovery tests

We don't just take backups — we test restoring from them and log the result, so recovery is proven, not assumed.

Change records

Meaningful changes to the platform are recorded, dated and attributable — a clear trail of what changed and when.

How we do business

Built by builders — we've felt every problem we're fixing.

SiteLive was built on real sites, by people who lived the chaos of supply overruns, missed confirmations and group-chat coordination. That's why our promises are simple and the same for everyone:

  • We tell you the truth — no false claims, no fake metrics, no aspirational features dressed up as real ones.
  • Your data is yours. We never sell it, never lock you in, and always let you export it for free.
  • Fair pricing, locked in, with no nasty surprises.
  • When you leave, you leave cleanly — your records come with you.
  • We answer real people. Running a review or hitting a problem? Email the team and you'll reach us.

— The SiteLive team

If you ever leave

A fair, predictable exit — never a hostage situation.

Construction records have to outlast a subscription. Here's exactly what happens to your data after you cancel — and you stay in control the whole way.

First 90 days

Your full archive is kept ready. One click reactivates everything — nothing lost.

90 days – 12 months

Data moves to lower-cost cold storage. Still recoverable on request, free.

After 12 months

Your choice: keep it on a small archive plan, or it's deleted on a published schedule — always with warning first.

Want a clean break? Our optional Clean Exit service packages your full archive, hands it over, then permanently erases your data from our systems and backups — in writing.

Where we stand today

  • Hosted on SOC 2 Type II and ISO 27001 certified cloud infrastructure
  • Encryption in transit and at rest
  • Per-site / per-organisation data isolation
  • Full, immutable audit trail
  • Role-based access control & SSO
  • You own your data — never sold, never used to train third-party AI
  • Australian Privacy Principles (APPs) compliant
  • GDPR-ready for UK and European users
  • Governed by Australian law; Australian Consumer Law applies
  • Independent penetration test scheduled — report will be published here

On the roadmap

  • Independent penetration test (annual, CREST-accredited)
  • Cyber liability insurance coverage
  • Published sub-processor list
  • Formal SOC 2 Type II attestation (our own)
  • ISO 27001 certification

Running a formal procurement or security review? We'll work through your questionnaire with you. Get in touch.

Roll it out with confidence.

Talk to us about an enterprise rollout, SSO, or a security review — we'll give you straight answers and the detail your team needs.