COSTiMO Back to home

Legal

Security Statement

Effective date: 15 May 2026
Website: costimo.ai
Application: app.costimo.ai

Costimo.ai is designed as a professional construction cost-management platform. We recognise that users may store and process confidential project, estimate, budget, vendor, and commercial information through the platform. This Security Statement summarises the general security approach followed by Costimo.ai.

Contents

  1. Security Commitment
  2. Cloud Infrastructure
  3. Access Control
  4. Data Protection Measures
  5. User Responsibilities
  6. Incident Handling
  7. Confidential Project Data
  8. No Absolute Guarantee
  9. Reporting Security Issues

1 Security Commitment

Costimo.ai uses reasonable technical and organisational measures to protect user accounts, project data, and platform infrastructure against unauthorised access, misuse, loss, alteration, or disclosure. Security is treated as an important part of platform development, hosting, access control, and operational maintenance.

2 Cloud Infrastructure

Costimo.ai uses cloud-based infrastructure and managed service providers for hosting, application delivery, storage, database, authentication, and related services. We aim to use reputable service providers with established security practices. However, security also depends on correct user configuration, access control, and responsible account management.

3 Access Control

Access to Costimo.ai is controlled through user accounts and authentication mechanisms. Depending on the applicable plan and configuration, Costimo.ai may support role-based access control, such as administrator, editor, viewer, or other permission levels.

Users and subscribing organisations are responsible for:

  • Assigning correct user roles and removing access for persons who no longer require it
  • Protecting login credentials and preventing credential sharing
  • Reviewing access permissions periodically

4 Data Protection Measures

Costimo.ai may apply the following security measures, where applicable:

Authentication & Access Controls

Controlled user authentication and role-based permission management.

Secure Cloud Hosting

Industry-standard cloud infrastructure with built-in security controls.

Encrypted Transmission

Encrypted data in transit where supported by the platform and infrastructure.

Logging & Monitoring

Application-level access logging and security monitoring.

Backup & Recovery

Backup and recovery arrangements to protect against data loss.

Regular Maintenance

Regular maintenance, dependency updates, and security patching.

5 User Responsibilities

Users are responsible for maintaining secure use of the platform, including:

  • Keeping passwords confidential and using strong login methods
  • Restricting account access to authorised personnel only
  • Reviewing project data before relying on it for decisions
  • Avoiding uploading of malicious files or unauthorised third-party data
  • Ensuring they have authority to upload confidential or third-party information
  • Promptly reporting suspected unauthorised access to us

6 Incident Handling

If we become aware of a security incident affecting user data or platform access, we will take reasonable steps to investigate, contain, and address the matter. Where required by applicable law or contractual obligation, we will notify affected users or organisations.

7 Confidential Project Data

Costimo.ai may contain commercially sensitive data such as tender estimates, resource rates, BOQs, budgets, cost-control records, and vendor information. Users should apply appropriate internal controls before granting access to such data. Costimo.ai should be used as part of a broader organisational cost-governance and approval process.

8 No Absolute Guarantee

While Costimo.ai applies reasonable security measures, no internet-based service, software system, or cloud platform can be guaranteed to be completely secure or uninterrupted. Users should maintain appropriate internal backups, approvals, and verification procedures for business-critical information.

9 Reporting Security Issues

If you discover a suspected security vulnerability, misconfiguration, or unauthorised access, please contact us promptly so we can investigate and respond appropriately.

Report a security concern

Email: admin@costimo.ai

Website: costimo.ai

Please include as much detail as possible. We aim to respond within two business days.

© 2026 COSTiMO.ai. All rights reserved. Privacy Policy Terms of Service Security