Skip to main content
Site Safety UAE — construction site safety software logoSite Safety UAE
Login

Security & privacy

Security controls built into every workspace

Site Safety UAE handles sensitive HSE evidence — permits, incidents, training records, and audit data. These are the platform controls enabled by default on every account.

Encrypted in transit & at rest

All traffic served over HTTPS. Data stored on managed Postgres with provider-managed encryption at rest.

Row-level access control

Every record is scoped to your organisation and site. Row-level security policies enforce access on the database, not just the UI.

Role-based permissions

Admin, manager, supervisor, and viewer roles. Roles are stored separately from user profiles and checked on the server.

Audit trail

Document versions, permit signatures, acknowledgements, and key actions are recorded with user, timestamp, and context.

Private document storage

Uploaded documents and photos live in private buckets. Access is granted via short-lived signed URLs — no public links.

Company-email access

Workspaces can be restricted to your company email domain. Invites and password resets go through verified email flows.

Shared responsibility

Site Safety UAE provides the platform controls listed above. Your organisation remains responsible for assigning roles correctly, off-boarding leavers, and managing the content uploaded to your workspace. We do not certify your HSE management system — we give your team the tools to evidence it.

This page describes capabilities enabled in the product. It is not an independent certification. For a copy of our data handling overview, contact the team below.

Security contact

info@sitesafetyuae.com

Report a suspected vulnerability or request a data handling overview.

Procurement and security review answers

The questions enterprise security reviews ask most often, answered plainly. Where a control is not in place we say so rather than implying it. Nothing here should be read as an independent certification.

Data location and residency Available
Application data is held in managed cloud infrastructure with a documented primary region. We confirm the current region in writing on request and notify enterprise customers before any change. Customer-controlled region selection is not currently offered.
Backups and recovery Available
The managed database is backed up on a rolling schedule with point-in-time recovery for the retention window on the current plan. Restore targets are agreed per enterprise contract; we do not publish a universal RTO/RPO we cannot evidence for every plan.
Data retention and deletion Available
Workspace owners can delete records and documents at any time. On account closure we delete workspace data and storage objects within 30 days, excluding backup copies which expire on their own retention cycle. A written deletion confirmation is available on request.
Subprocessors Available
We maintain a current list of subprocessors covering hosting, database, email delivery, payment processing and optional AI services. The list is provided with the security pack and is available before contract signature.
Incident handling and notification Available
Security events are triaged by the founding engineering team. Confirmed incidents affecting customer data are notified to workspace owners without undue delay, with the facts known at the time and follow-up once the review closes.
Access control and audit trail Available
Access is role-based and enforced in the database itself, not only in the interface. Document access uses private storage with short-lived signed URLs, and sign-off, export and administrative actions are written to an audit log you can export.
Availability measurement Available
Uptime is monitored continuously with automated outage alerting and a public health endpoint. A contractual availability SLA is offered on Enterprise agreements only; there is no SLA on Free or Pro.
Independent penetration test or certification Not currently offered
We have not completed an independent penetration test, and we hold no ISO 27001 or SOC 2 certification. We do not claim otherwise. Automated dependency and platform security scanning runs against every release, and results can be discussed under NDA.
Vulnerability reporting Available
Report suspected vulnerabilities to info@sitesafetyuae.com. We acknowledge within two business days, keep the reporter informed, and do not pursue good-faith researchers who avoid privacy violations, data destruction and service disruption.
Privacy, DPA and data-processing route Available
A data processing agreement is available for signature before onboarding, covering processing purposes, subprocessors, security measures, breach notification and deletion on termination. UAE PDPL-aligned; we do not claim any certification of compliance.
Single sign-on and directory sync Not currently offered
SSO is available on Enterprise agreements. Automated SCIM directory provisioning and deprovisioning is not currently offered; user lifecycle is managed by workspace admins.
AI processing and oversight Available
AI features are optional and can be disabled per workspace. AI output is a draft suggestion requiring review by a competent person, is never treated as an authority approval, and customer content is not used to train third-party models.

Request the security pack

Qualified buyers can request the subprocessor list, DPA, data-flow summary and control responses for their own review template. We reply with the current documents rather than a marketing summary.

Request security pack

Next step

Turn this into evidence you can hand over

Replace scattered spreadsheets and WhatsApp threads with one HSE operations system built around UAE authority expectations.

  • Built around UAE authoritiesADOSH-SF, Trakhees, DM, DCD, MOIAT and ISO 45001 structures.
  • Usable the same dayTemplates and registers are pre-filled with your company details.
  • Evidence, not just formsEvery record carries dates, signatures and an export you can hand over.