Architecture and Data Security
CxCheck is built as a sovereign service. Document analysis runs on hardware we own and control - your documents are never sent to third-party AI providers and are never used to train public models.
Commissioning documents are stored under per-organization isolation and are readable only by people you have invited to that project. We do not sell, share or syndicate customer documents to any third party. For approved enterprise projects, CxCheck can be deployed on dedicated hardware inside your own facility.
Two deployment modes
There are two ways to run CxCheck. One is the standard service and is how the platform is delivered. The other is in development and is scoped per engagement. We describe both plainly so that a vendor review can tell which one applies to a given project.
| Sovereign Hosted | On-Site Node | |
|---|---|---|
| Availability | Available now - the standard service. | In development. Available for approved enterprise projects. |
| Where documents are stored | On storage operated by CxCheck, isolated per organization at the database layer. | On the node inside your facility, on storage you physically hold. |
| Where inference happens | On CxCheck-owned hardware running local models. No third-party model API is called with your documents. | On the node itself, inside your network boundary. |
| What leaves your network | The documents you choose to upload, over TLS, to CxCheck. Nothing is forwarded onward to a model vendor. | Nothing, other than the update and licensing traffic you permit. The exact outbound endpoints and ports are available in writing on request. |
| Who has access | Users you invite to the project, plus named CxCheck operations personnel for support and maintenance. | Your staff. CxCheck access only through a support path you authorise. |
| Commercials | Included in standard subscription plans. | Hardware supplied pre-configured, licensed on a subscription basis. Scoped per engagement. |
Sovereign Hosted is the standard service. You upload commissioning documents through the web application over TLS. They are stored on infrastructure CxCheck operates, scoped to your organization by row-level security in the database, so a user belonging to one organization cannot read another organization's records. Analysis is performed by models running on hardware we own; the document text is not relayed to an external model API at any point in that path.
On-Site Node inverts the boundary. CxCheck supplies a pre-configured appliance that is installed and operated inside your own facility, on your network, under your physical control. Documents are stored on that appliance and inference runs on it. This tier is in development, is agreed in writing before onboarding, and is subject to technical review of your environment. It is not the standard delivery model, and we will not describe a hosted project as if it were on-site.
What we never do
No third-party AI providers
Customer documents are never sent to OpenAI, Anthropic, Google or any other hosted model API.
No training on your data
Your documents are never used to train any model - ours or anyone else’s - and are never pooled across customers.
No sharing or resale
Documents are never shared with third parties for analytics, marketing, benchmarking or any other purpose.
What is live today
This section describes the service as it actually runs right now, not a roadmap. Where a specific has not been formally documented, we leave it out here and provide it in writing on request rather than guess.
- AI inference: document analysis runs on CxCheck-owned hardware using locally hosted models. Model family, hardware specification and the physical location of that hardware are available in writing on request.
- Application and database hosting: the web application, project records and document storage currently run on managed cloud infrastructure operated on CxCheck's account, with per-organization row-level security. Provider and data region are available in writing on request. This component is planned to move to self-hosted infrastructure alongside the inference hardware.
- Authentication: handled by the same managed platform as the database. Sign-in credentials and session tokens pass through it; commissioning documents do not.
- Transactional email: a third-party email delivery provider sends invitations and notifications. It receives names, email addresses and notification text, never document contents. The provider is named in the subprocessor list, available in writing on request.
- Payments: subscription billing is handled by a third-party payment processor which receives billing details only, never project data. The processor is named in the subprocessor list, available in writing on request.
- Not in the data path: no hosted general-purpose AI API receives customer document content.
If your review requires a signed statement of the current data path, ask us for it in writing. We would rather answer a hard question accurately than let a marketing page answer it for us.
Procurement and security questions
These are the questions a bank, an operator or a main contractor's vendor review normally asks. The answers below are the ones we give in a security questionnaire.
Where is the hardware and how is it physically secured?
Inference hardware is owned by CxCheck. The facility, jurisdiction and the physical access controls at that site are available in writing on request, and we will describe the arrangement under NDA for any project that requires it.
Who at CxCheck can access customer documents?
Access is limited to named operations personnel who require it for support and maintenance. CxCheck is a small specialist vendor, so that list is short and is provided by name on request, along with how access is approved. Application-level access by any other user is blocked by per-organization row-level security. Administrative access events are recorded, and the retention period for those logs is available in writing on request.
How is data encrypted, at rest and in transit?
All traffic between your browser and CxCheck is encrypted in transit using TLS. Stored documents and database records are encrypted at rest by the storage layer. Specific algorithms, key lengths and key management are available in writing on request. We would rather answer that precisely than state a standard we have not verified on a marketing page.
Where are backups held and are they encrypted?
Backups are taken of the project database and document storage. Backup frequency, retention, storage location, encryption and restore testing cadence are available in writing on request.
How long is data retained, and how is deletion evidenced?
Project data is retained for the life of the engagement. On written request we delete a project or an organization's data and confirm completion in writing. Standard retention period after contract end, the lag before deleted data ages out of backups and the form of deletion evidence provided are available in writing on request.
What is the availability commitment, and what happens if hardware fails mid-project?
We do not publish an uptime figure we cannot evidence. Any contractual availability target is agreed in writing per engagement. If inference hardware fails, document analysis is unavailable until it is restored; project records, checklists and issues remain accessible, and commissioning work continues in the application. Target restoration time and the spare-hardware arrangement are available in writing on request. Being honest about it: a single specialist vendor running its own hardware does not have the failover depth of a hyperscaler. That is the trade-off. You get a data path with no third-party model provider in it, in exchange for a smaller operational surface.
What about business continuity and key-person risk?
CxCheck is a small team, and pretending otherwise would not survive your first reference call. Key-person risk is real and we address it contractually rather than by claiming scale we do not have. Escrow, handover and continuity arrangements, along with documented export formats and exit assistance terms, are available in writing on request. Your data is exportable at any time in standard formats, so an exit does not strand a project.
Who are your subprocessors?
No AI model provider is a subprocessor, because no model provider processes your documents. The remaining subprocessors are those listed under “What is live today”: a managed cloud database, storage and authentication provider; an email delivery provider; and a payment processor. A current named list with processing locations is available in writing on request.
Do you hold any security certifications?
CxCheck holds no third-party security certification at this time. Our current position on frameworks such as ISO 27001 and SOC 2 is available in writing on request. We will not claim a certification we do not hold, and we will tell you directly if a certification is a requirement we cannot currently meet.
Why this matters for commissioning
Commissioning scope is not limited to chillers and switchgear. On a typical data centre or hospital project it includes the fire detection and alarm system, the access control system, CCTV head-end configuration and the integration matrix that ties them to the BMS. The documents describing those systems are not ordinary engineering drawings.
A cause-and-effect matrix states exactly which detector triggers which damper, which doors release on alarm, and under what sequence. An access control submittal identifies controlled doors, reader locations and override paths. A security system riser shows camera coverage and, by omission, where coverage is thin. Read together, these documents are an operational description of how to move through a critical facility without being detected or obstructed.
When a commissioning engineer pastes that content into a general-purpose cloud AI tool to speed up a script review, the exposure is not only a data privacy question. The material has been copied to infrastructure the asset owner has not assessed, cannot audit and may not be able to compel deletion from. For an owner whose threat model includes physical intrusion, that is a physical security incident that happened to occur over HTTPS.
This is why CxCheck runs analysis on hardware we own rather than brokering it to a model vendor. It is also why the On-Site Node tier exists: for owners whose policy is that FDAS and security documentation does not leave the site perimeter at all, the only honest answer is to put the hardware on the site.
Send us your vendor questionnaire
We will answer it line by line, including the specifics we provide in writing rather than publish.
Talk to us