Company

Compliance

Last updated: 8 October 2026

This page describes how ForensicBIM meets its legal and ethical obligations: how we secure and protect data, which standards our Service is built on, how we handle export controls and sanctions, and the principles we follow in doing business. It is written for customers, procurement teams and auditors who need to assess ForensicBIM as a supplier.

At a glance

  • Our security controls are designed around SOC 2 and ISO/IEC 27001. We do not yet hold a certification or an independent audit report, and no audit is scheduled.
  • We are based in the Netherlands and comply with the GDPR. Our Data Processing Agreement forms part of our Terms of Service.
  • The Service works with IFC (ISO 16739-1), and our valuation methodology refers to IAS 38, GASB 51 and RJ 210.
  • Sanctioned countries and persons may not use the Service. Stripe screens Pro payments; we check Enterprise customers before contracting.
  • Security issues and compliance concerns can be reported to support@forensicbim.business.

1. Security and privacy compliance

ForensicBIM's security programme is designed around the AICPA Trust Services Criteria used in SOC 2 reports, ISO/IEC 27001 and the NIST Cybersecurity Framework 2.0. We have written policies for information security, access control, incident response, disaster recovery, change management, vendor risk, and data retention and disposal.

We do not yet hold an ISO/IEC 27001 certificate or a SOC 2 report, and no independent audit is currently scheduled. On request, and under confidentiality, we share our security policies, a summary of our controls and answers to security questionnaires.

Trust Services Criterion How we address it
Security Multi-factor authentication and least-privilege access for staff; logging of administrative actions and staff downloads, kept for 12 months; Content Security Policy, HSTS and other security headers; sessions that end after 60 minutes of inactivity; and automated checks for leaked secrets, vulnerable dependencies and insecure code on every change to the main code branch and every week (Gitleaks, pip-audit, npm audit, Bandit, Semgrep, Trivy and an OWASP ZAP baseline scan).
Availability Managed Google Cloud infrastructure in eight regions, an automated platform watchdog that runs every 10 minutes, and documented incident response and disaster recovery plans. Availability commitments are offered only under an Enterprise agreement.
Processing integrity Automated unit and end-to-end test suites before deployment; each file is analysed by a dedicated worker in the selected region; an analysis that cannot be completed is marked as failed rather than processed elsewhere; optional schema validation by buildingSMART.
Confidentiality Model files stored and analysed in the region the customer chooses; encryption in transit and at rest; staff access to models only for support, security, legal reasons or algorithm improvement where the customer's setting allows it, with every download logged.
Privacy A published Privacy Policy and Data Processing Agreement, self-service deletion of analyses and accounts, and a listed set of sub-processors.

More detail is available in our Trust Centre and in Annex 2 of the Data Processing Agreement.

2. Data protection (GDPR)

  • ForensicBIM is based in Amsterdam, the Netherlands, and is subject to the EU General Data Protection Regulation and the Dutch GDPR Implementation Act. Our supervisory authority is the Autoriteit Persoonsgegevens.
  • For personal data contained in customer models, we act as a processor under our Data Processing Agreement, which forms part of our Terms of Service. A signed copy is available on request.
  • Customers choose the region where their model files are stored and analysed. Transfers outside the European Economic Area are covered by the EU Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.
  • We notify customers of a personal data breach affecting their data within 48 hours of becoming aware of it.

3. Standards we work with

Standard How it is used
IFC (ISO 16739-1) The open buildingSMART standard for building and infrastructure data. ForensicBIM analyses IFC2X3, IFC4 and IFC4.3 files.
buildingSMART Validation Service Optional official schema and syntax validation of uploaded files, run by buildingSMART International.
IAS 38 (IFRS) Recognition and measurement concepts for intangible assets, used in our valuation methodology for organisations reporting under IFRS.
GASB Statement No. 51 Accounting for intangible assets by US state and local governments, used in our valuation methodology for public sector asset owners.
RJ 210 (Dutch GAAP) Dutch guideline for intangible fixed assets, used in our valuation methodology for organisations reporting under Dutch GAAP.

Our valuations are automated estimates that support, but do not replace, the judgement of the customer's accountants and auditors. See our methodology.

4. Export controls and sanctions

  • We comply with the export control and sanctions laws of the European Union, the Netherlands, the United Kingdom and the United States that apply to our business.
  • Our Terms of Service do not allow use of the Service from, or for the benefit of a person in, a country or region subject to comprehensive sanctions, or by a sanctioned person or organisation.
  • Pro subscriptions are paid through Stripe, which screens payments against sanctions lists.
  • We check Enterprise customers against sanctions requirements before entering into an agreement.
  • Customers may not upload export-controlled technical data or classified information.

5. Business conduct

  • Anti-bribery and corruption. We do not offer, give, ask for or accept bribes, kickbacks or facilitation payments, directly or through others.
  • Public officials. We offer gifts or hospitality to public officials only where the rules of their organisation allow it, and never to influence a decision.
  • Fair procurement. We follow the procurement rules of the public bodies we work with and do not seek confidential information about competing bids.
  • Conflicts of interest. Our staff and advisers disclose any personal or business interest that could conflict with their work for a customer.
  • Fair competition. We comply with competition law and do not agree prices or divide markets with competitors.
  • Independent results. Scores and valuations are calculated automatically. We do not adjust them to favour any customer.

6. Human rights and suppliers

We do not tolerate forced labour, child labour or human trafficking in our business or among our suppliers, and we would end a supplier relationship over it. Our main suppliers are cloud, payment and software providers. We review them when we start working with them and once a year after that, under our vendor risk policy.

ForensicBIM is not required to publish a statement under the UK Modern Slavery Act 2015 or similar laws. We set out these commitments voluntarily.

7. Information for public sector buyers

For procurement and supplier assessments, we provide:

  • our Terms of Service, Privacy Policy and Data Processing Agreement, including a signed copy of the DPA;
  • the list of sub-processors and the regions where data is stored;
  • security policies, a controls summary and answers to security questionnaires, under confidentiality; and
  • contract changes that the law requires for public bodies, such as on governing law or public access to information (section 19 of the Terms).

8. Reporting security issues and concerns

Security vulnerabilities. If you find a vulnerability in the Service, email support@forensicbim.business with the subject "Security report" and enough detail for us to reproduce it. Please do not access other users' data, disrupt the Service or make the issue public before we have fixed it. We will confirm receipt and keep you informed, and we will not take legal action against anyone who reports in good faith and follows these guidelines.

Compliance concerns. Concerns about bribery, sanctions, data protection or human rights can be sent to the same address. We treat reports confidentially and do not tolerate retaliation against anyone who raises a concern in good faith.

9. Contact

ForensicBIM
Claude Debussylaan 82-84
1082 MD Amsterdam
The Netherlands
Email: support@forensicbim.business

Back to top ↑