How we handle data

We don’t hold what we don’t need.

GroundWork is built on a deliberate principle: the sensitive details of your premises never leave your device. A central store of sites’ layouts and vulnerabilities is exactly what the legislation exists to protect - so we didn’t build one.

STAYS ON YOUR DEVICE

Sensitive · never transmitted to us

  • Marked locations - exits, routes, assembly and invacuation points
  • Your evacuation, invacuation, lockdown and communication procedures
  • Connectivity assessments tied to locations
  • Descriptions of layout, access and movement
  • Security and equipment details
  • Your signature
  • The finished readiness document (PDF)

Created - and fingerprinted - inside your browser. We can’t retrieve it, because we never receive it.

COMES TO US

Non-sensitive index · to enable verification

  • Site number and document reference
  • Version, type, tier and status
  • Organisation name, category, town, postcode and UPRN
  • Company number, where applicable
  • Responsible person name and contact email
  • Dates - created, reviewed and review-due
  • A cryptographic fingerprint (hash) of the document

No coordinates. No procedures. No floor plans. Nothing describing how your premises is laid out or protected.

The line between the two is simple: public identifiers and limited verification metadata can be indexed; anything describing how your premises is laid out, operated or protected stays with you.

How verification works

Confirm a document is genuine - without us ever holding it.

Because we hold a cryptographic fingerprint of each document, its authenticity can be confirmed without us ever holding the document itself.

01

A reference is presented

Someone scans the QR code on a document, or enters its reference at our verification page.

02

We check the index

The reference is matched against our non-sensitive index of issued documents.

03

We confirm status only

A limited, non-sensitive result is returned - never the contents of the document.

"genuine": true, "organisation": "The Old Granary",
"version": "STD-1.0", "status": "active",
"created": "2026-08-16", "review_due": "2027-08-16"
// no contacts · no locations · no procedures · no content

One-off verification lets anyone you show a document to - an event organiser, a partner or an inspector - confirm it is genuine, its version, its status and when it was created.

Bulk verification lets an authorised party holding a set of references - for example an insurer whose customers have given them their references - confirm authenticity and currency across many documents at once. It returns only non-sensitive validation data, never the contents of any document.

Verification confirms that a document is genuine and when it was created. It does not certify the document’s contents or confirm compliance with the law.

Sharing with insurers

The site stays in control.

References come from customers

An insurer must obtain the relevant document references from their own customers - the sites themselves. We do not provide, sell or supply lists of customers or references to insurers.

Only non-sensitive data returned

Validation returns existence, status, version, dates and organisation identity for matching. It never returns premises detail, procedures or locations. Access is granted only to authorised parties, and can be withdrawn.

An insurer can only validate a document whose reference the site chose to give them.

No sale · no AI training

What we never hold can’t be sold, shared or used to train a model.

We do not sell your data. We do not share it for advertising or marketing. We do not use it, and do not permit it to be used, to train artificial intelligence or machine-learning models.

This isn’t only a policy - it’s structural. Because your sensitive premises data is never stored on our servers, there is no dataset of it for any AI or language model to be trained on - ours or anyone else’s. The protection is built into how the system works.

Ready to keep your record in your hands?

Build a structured readiness document without creating an account or handing over sensitive premises detail.