SECURITY & TRUST

Evidence first. Claims second.

A compact due-diligence centre covering hosting, access controls, data ownership, subprocessors, incidents and procurement status.

Security model

Hirentra is a multi-tenant construction SaaS product. Access is controlled using authenticated accounts, company/tenant boundaries, role/capability controls and site-scoped permissions. Security-sensitive server operations are intended to be enforced server-side rather than relying on hidden buttons in a client.

Data infrastructure

Core application database, authentication and storage services are provided using Supabase. Web delivery/security and supporting services use named providers listed on the Subprocessors page. Customer-specific hosting/residency commitments are confirmed during contracting rather than implied by marketing copy.

Security & resilience

Hirentra applies layered security and operational-resilience controls across identity, tenant access, evidence storage, backup/recovery and audit.

Multi-factor authentication: Privileged Hirentra roles require multi-factor authentication (MFA); MFA is optional for field users.

Database-enforced tenant isolation: Tenant isolation is enforced server-side using database permissions, Row Level Security (RLS) and company/site access controls — not only through the user interface.

Private evidence storage: Evidence and operational file storage is private and is not exposed through public object URLs.

Independent backup and recovery controls: Independent database and storage backup copies are maintained separately from the production environment, with backup health, integrity checks and restore testing forming part of Hirentra's operational-readiness controls.

Audit trails: Hirentra maintains database-backed audit trails for key operational, governance and commercial activity.

Pilot and production-readiness evidence is retained internally as appropriate. Detailed technical evidence can be shared during reasonable customer due diligence where disclosure would not weaken security or expose another customer's information.

Data ownership, export and deletion

Customer project data remains the customer's data. Pilot and subscription agreements define export and close-out handling. Hirentra's standard Pilot Terms provide an exit/export period rather than trapping a customer inside the service.

Incidents and breach handling

Security incidents are assessed and recorded. Where a personal-data breach affects Customer Personal Data, Hirentra's DPA requires notification to the affected customer/controller without undue delay after Hirentra becomes aware.

Procurement status

ICO: an ICO registration reference will be published only after the applicable registration has been completed and a reference issued.

Professional indemnity / cyber insurance: Hirentra will state insurance as “insured” only when current cover is actually in force and evidenced by a certificate. Certificates can then be supplied during procurement on request.

VAT: VAT details will be shown on relevant commercial documents when TheBigBangWorks Ltd is VAT registered. The website does not present a VAT number before registration exists.

Responsible claims

Hirentra does not describe customer-specific ERP integrations as certified, production-ready or universally compatible until that customer's landscape has been scoped and validated. Demonstration screenshots are labelled where they contain illustrative data.

Security / procurement contact

For due-diligence questions, DPA requests or security documentation, contact hello@hirentra.com.

Last updated: 20 September 2026.