Security and Certifications
Protecting customer data is fundamental to Asite.
Asite is committed to maintaining high standards of information security, privacy, resilience and compliance. Our security programme is supported by internationally recognised certifications, secure cloud architecture, and industry best practices that help organisations protect their information throughout the Project lifecycle.
This section provides an overview of Asite's security certifications, compliance standards, platform architecture, and data protection measures.
Certifications
Australian Defence Industry Security Program (DISP)

 

The Australian Government's Defence Industry Security Program (DISP) recognises organisations that meet strict security requirements for working with Australia's defence security.

 

Asite Solutions Ltd is an approved DISP member, demonstrating compliance across four key security disciplines:

 

1. Governance

2. Personnel

3. Physical Security

4. Information and Cyber Security

 

Membership is granted following an assessment by the Australian Government and remains ongoing, provided the organisation continues to meet the program's security obligations. Asite Solutions Ltd currently holds Entry Level (EL) membership across all four security disciplines.

Cyber Essentials

 

Cyber Essentials is a UK Government-backed certification that helps organisations protect against the most common cyber threats by demonstrating the implementation of fundamental cyber security controls.

 

Asite Solutions Ltd has achieved Cyber Essentials Certification, confirming that the organisation meets the requirements of the Cyber Essentials scheme across its entire organisation. The certification is awarded following an independent assessment of key cyber security controls designed reduce the risk of common internet-based attacks.

Cyber Essentials Plus

 

Cyber Essentials Plus is the highest level of certification within the UK Government-backed Cyber Essentials Scheme. It builds on Cyber Essentials by independently verifying that an organisation's cyber security controls are operating effectively through hands-on technical testing.

 

Asite Solutions has achieved Cyber Essentials Plus Certification, demonstrating that its cyber security controls have been independently assessed and tested against common cyber threats. The certification is applied across the organisation and provides additional assurance that key measures are not only implemented but are also operating effectively in practice.

Ministry of Defence Cyber Defence & Risk (CyDR)

 

The Ministry of Defence Cyber Defence & Risk (CyDR) accreditation recognises systems that have been independently assessed against the UK Government and Ministry of Defence cyber security requirements.

 

Asite Solutions has been granted Full CyDR Accreditation, demonstrating that the platform has satisfied the cyber security requirements defined by Her Majesty's Government (HMG) and the UK Ministry of Defence (MOD). Accreditation is awarded following a formal security assessment and is subject to ongoing review in accordance with the applicable accreditation requirements.

ISO 19650 Kitemark Certification

 

Asite has been awarded the BSI Kitemark for BIM Software, recognising its support for organisations working in accordance with the ISO 19650 framework for information management throughout the lifecycle of built assets.

 

The certification is awarded following an independent assessment of the platform's software functionality, security-minded approach, user support, development practices, and organisational resilience. It confirms that the Asite Common Data Environment (CDE) supports the key requirements of the ISO 19650 standards for collaborative information management.

 

This certification covers Asite's Project Portfolio Management (PPM): Common Data Environment (CDE) solution and demonstrates its alignment with BS EN ISO 19650-1:2018, BS EN 19650-2:2018, and BS EN ISO 19650-5:2020.

ISO/IEC 27001:2022 Information Security Management System

 

ISO/ IEC 27001: 2022 is the internationally recognised standard for Information Security Management Systems (ISMS). It provides a structural framework for identifying, managing and continually improving information security risks across an organisation.

 

Asite's Information Security Management System has been independently certified by BSI against the ISO/IEC 27001:2022 standard. The certified scope covers the protection of customer data throughout the development and delivery of Asite's Software as a Service (SaaS) platform, including controls that maintain the confidentiality, integrity, availability and accountability of information for clients and partners worldwide.

 

The certification applies across Asite's global operations, providing a consistent information security management framework spanning the United Kingdom, Australia India, the United Arab Emirates, Saudia Arabia, the United States, and Hong Kong.

Information Commissioner's Office (ICO) Registration

 

The Information Commissioner's Office (ICO) is the UK's independent authority responsible for upholding information rights and enforcing data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Asite Solutions is registered with the ICO as a data controller, demonstrating its commitment to handling personal data responsibly and in accordance with UK data protection legislation. The registration confirms that Asite has formally registered its data processing activities with the UK's data protection regulator and has appointed a dedicated Data Protection Officer (DPO) to oversee data protection compliance across the organisation.

 

ICO registration provides customers with assurance Asite operates within the UK's regulatory framework for personal data protection and maintains clear accountability for the collection, processing, storage, and management of personal information.

Platform Architecture and Data Protection

Technical Architecture

Asite is designed using a resilient, cloud-based architecture that prioritises availability, performance, and data protection. The platform incorporates multiple layers of security, redundancy, and infrastructure management to help ensure reliable access while protecting customer information throughout its lifecycle.

 

The platform uses a standardised architecture that reduces operational complexity, simplifies maintenance, and improves resilience. Security controls such as DDoS protection, Web Application Firewalls, load balancing, encrypted storage, clustered databases, and enterprise search services work together to deliver a secure and highly available service.

 

Data is encrypted both at rest and in transit, with production and backup environments separated to support business continuity. Customer data is hosted within the selected geographic region, with UK-hosted environments remaining within the UK. The platform also provides regional hosting options across multiple global locations to support data residency requirements.

 

Authentication supports modern identity management, including Single Sign-On (SAML v2) and Multi-Factor Authentication (MFA), enabling organisations to integrate with their existing identity providers while maintaining secure access to the platform. Administrative access is further protected through privileged access management, multiple layers of authentication, and comprehensive auditing.

The platform uses a modular, microservices-based architecture that enables independent services to communicate efficiently while maintaining high availability, flexibility, and scalibility. Enterprise messaging services, distributed storage, and globally replicated cloud infrastructure ensure reliable performance for organisations of all sizes. 

 

Asite for Architects is built on the Asite Business Operating System (ABOS), and cloud-native platform designed to support, secure, scalable, and high-performance information management across the built environment. The platform combines document management, workflow automation, BIM, reporting, integrations, and asset information management within a single architecture.

security-data-privacy
Why is Asite the preferred Common Data Environment?
Security and Data Privacy by Design and by Default

Blogs

5 Reasons Organisations Move to Asite vs Other Solutions

Construction projects generate an enormous volume of information. Choosing the wrong software to manage that information will put compliance and accountability at risk. Every document needs a clear...
Asite

Blogs

Building Confidence in Construction Technology: Lily’s Journey at Asite

In this blog, we explore Lily-Rose Davies' journey into construction technology and how her internship at Asite is helping her build practical skills, confidence, and a new perspective on careers in...
Venus Wu

Blogs

25 Years of Asite: Building the Future of Construction Collaboration

25 years ago, Asite was founded on a simple belief: construction projects work better when everyone works from the same information. That belief remains as relevant today as it was in 2001. Over...
Asite