Photo report in seconds instead of photo chaos
31.03.2026
One Year of ISO 27001: First Surveillance Audit Successfully Passed
20.07.2026Published: June 2025
In civil engineering, sensitive data is processed daily: pipeline routes, existing plans, georeferenced recordings of critical infrastructure. Once this data is in a digital application, the central question is no longer availability, but security: How is it transferred, stored, and protected from unauthorized access?
SitePlan now answers this question with an internationally recognized certification: We are certified ISO/IEC 27001 certified – the leading standard for an Information Security Management System (ISMS).
The Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022 ensures the confidentiality, integrity, and availability of customer data, supplier information, and SitePlan's internal data related to its cloud-based surveying and geo-documentation services, including GPS-based surveying, setting out, geo-referenced photo documentation, and data synchronization within the SitePlan platform.
What the certification concretely means
An ISMS is not a one-time certification, but a risk-based management system. It includes documented security policies, risk management with defined treatment measures, and security controls anchored in the standard (Annex A). Effectiveness is regularly reviewed through external audits.
Security Measures for Your Data
- Encryption during transmission and storage – Project data is encrypted both in transit and at rest.
- Role-Based Access Control (RBAC) according to the principle of least privilege – each user receives only the permissions required for their role.
- Data sovereignty and purpose limitation Your data remains your responsibility. Processing will be carried out exclusively for project management purposes, without disclosure to third parties – in accordance with the principles of the GDPR.
Relevance in Civil Engineering
Those who work for public contracting authorities, network operators, or railway infrastructure process sensitive, sometimes critical infrastructure data. Large contracting authorities are increasingly requiring a reliable proof of security from their subcontractors as well. ISO/IEC 27001 certification provides this proof in a form that is recognized in tenders and supplier assessments – one reason why companies like PORR, STRABAG, and Deutsche Bahn rely on SitePlan.
Questions about our information security or the scope of certification?
Contact us – or learn SitePlan in a personal demo. Non-binding and free of charge.
