← Back to SiteLive
Trust & data security

Trust & Data Security

The questions a serious builder asks before rolling software across every site: where data lives, how it's protected, who can see it, and what happens when you leave. Here are the straight answers.

How your data is protected

SiteLive runs on enterprise-grade cloud infrastructure that is independently certified to SOC 2 Type II and ISO 27001. Your data is encrypted in transit and at rest, with automated backups so nothing is lost.

Access & accountability

People only see the sites they're on. Roles control what each person can do, and every meaningful change is written to an immutable activity trail.

Sign-in & identity

Use email and password or Google out of the box. Enterprises can connect their own identity provider with SAML single sign-on.

Data ownership & exit

You own your data — we never sell it and never use it to train third-party AI. You can export it for free at any time while your account is active.

Infrastructure you can verify

Built on infrastructure that is already audited.

We do not self-host. SiteLive runs on managed cloud providers that publish their own compliance reports — so the security of the underlying platform is independently verified, not just promised.

SOC 2 Type II

Our hosting provider maintains an active SOC 2 Type II attestation covering security, availability, and confidentiality.

ISO 27001

The same infrastructure is certified to ISO 27001, the international standard for information security management.

Australian Privacy Principles

We are structured to comply with the Australian Privacy Act and the 13 APPs. Australian Consumer Law applies and is non-excludable.

GDPR-ready

Data export, right to deletion, and breach notification processes are built in for any UK or European users on your sites.

Running your own vendor review? We can share our sub-processor list and host security documentation under NDA. — request it at team@sitelive.group.

Single sign-on

Sign in with the identity you already trust.

Everyone starts with email/password or Google out of the box. For larger rollouts, connect your own identity provider with SAML single sign-on — so access follows your existing joiner/leaver process, not a separate password list.

AI you can trust

The AI works for you — on your data, and only your data.

SiteLive's AI reads the live bookings, dockets, diaries and records you already capture to answer questions and draft reports. It never guesses on your behalf when the facts aren't there, and it never learns from your data to help anyone else.

Grounded in your records

Answers and reports are built from your own live data — not the open internet — so what you read reflects what's actually on your site.

Never trains third-party models

Your data is never sold and never used to train external AI. It stays yours, used only to run SiteLive for you.

Traceable & reviewable

AI output is logged. Every generated report is attributable — you can see when it was produced and check it against the source.

Always your call

AI drafts and surfaces; people decide. Docket reads and reports are presented for you to confirm before they count.

Price-lock promise

The price you start on is the price you can plan on.

Your rate is locked for 12 months from the day you subscribe. If it ever changes after that, the change will be small — only ever to cover hosting and storage — and we'll tell you well in advance. No surprise hikes, ever.

Run like a company that's here to stay

We keep our own house in order — and keep the receipts.

Behind the product we keep dated, internal governance records — the same controls a SOC 2 or ISO 27001 assessor looks for. Not because we have to yet, but because the business you rely on should be run properly from day one.

Access reviews

We review who can reach systems on a regular cadence and record it — so access stays tight as the team changes.

Vendor register

Every sub-processor and tool we rely on is tracked, with its own security posture noted and reviewed.

Disaster-recovery tests

We don't just take backups — we test restoring from them and log the result, so recovery is proven, not assumed.

Change records

Meaningful changes to the platform are recorded, dated and attributable — a clear trail of what changed and when.

How we do business

Built by builders — we've felt every problem we're fixing.

SiteLive was built on real sites, by people who lived the chaos of supply overruns, missed confirmations and group-chat coordination. That's why our promises are simple and the same for everyone:

— The SiteLive team

If you ever leave

A fair, predictable exit — never a hostage situation.

Construction records have to outlast a subscription. Here's exactly what happens to your data after you cancel — and you stay in control the whole way.

First 90 days

Your full archive is kept ready. One click reactivates everything — nothing lost.

90 days – 12 months

Data moves to lower-cost cold storage. Still recoverable on request, free.

After 12 months

Your choice: keep it on a small archive plan, or it's deleted on a published schedule — always with warning first.

Want a clean break? Our optional Clean Exit service packages your full archive, hands it over, then permanently erases your data from our systems and backups — in writing.

Where we stand today

On the roadmap

Running a formal procurement or security review? We'll work through your questionnaire with you. — get in touch at team@sitelive.group.

Roll it out with confidence.

Talk to us about an enterprise rollout, SSO, or a security review — we'll give you straight answers and the detail your team needs. — talk to us at team@sitelive.group.