Security & Trust

Last modified: 08/14/2026

CMIS is built and operated with one fact in mind: public agencies trust us to hold sensitive project, contractor, and inspection data on their behalf. Every safeguard on this page exists because that responsibility is real, not because a compliance checklist requires it.

Data Protection

Data is encrypted both in transit and at rest, using industry-standard encryption methods that meet current best-practice standards. This applies across the platform — no exceptions for convenience.

Access Control

Access to CMIS follows the principle of least privilege. Role-based permissions mean each user sees only the projects and functions their role requires, and every new user goes through an approval workflow before access is granted — nothing is self-service. Agency administrators can review who has access at any time and revoke it immediately when someone no longer needs it. Accounts that go unused for an extended period are automatically deactivated, so departures and staff turnover never leave an open door.

Backups and Continuity

CMIS data is backed up on a regular, ongoing schedule, and our recovery procedures are documented and tested — not theoretical. Should the unexpected happen, restoring your project data is a practiced process, not an improvised one.

Hosting and Infrastructure

CMIS runs on professionally managed cloud infrastructure with physical and network safeguards appropriate to the sensitivity of the data we hold. We work with established, reputable providers and hold them to the same standard we hold ourselves.

Compliance Posture

CMIS's security practices are aligned with recognized industry frameworks and reviewed against them regularly. We contract independent, third-party penetration testing of the CMIS platform on an annual basis through Fortra's Digital Defense. Our most recently completed assessment rated CMIS's overall security posture as Good, and every finding identified — each one low severity — was confirmed remediated through an independent follow-up retest. We don't yet hold a formal third-party certification such as SOC 2 — we'll say so plainly rather than imply otherwise — but our controls are built to that standard, and we're glad to discuss where we stand against any framework your agency requires.

Ongoing Practices

Security isn't a one-time setup at CMIS. Systems are patched, monitored, and reviewed on an ongoing basis, and our practices evolve as standards and threats do.

Need More Detail?

A public page can only responsibly say so much — and we know compliance and IT security reviewers often need more. If your agency needs a fuller security documentation packet — architecture detail, testing reports, or answers to a formal questionnaire — contact us directly and we'll work with your procurement or IT security officer to get you what you need, typically under NDA or through a verified agency contact.

Contact

Construction Management Enterprises
P.O. Box 67
Elk Grove CA, United States 95759
contact@c-mis.com
+1 (530) 207-0083
https://c-mis.com