Verify site readiness - programmatically, at scale.

API & agent access

For teams that want validation built into their own tools, we've developed a programmatic API - and support for agent-based MCP access - so status checks run automatically within your systems.

  • Batch validation via API
  • Structured results into your CRM or ERP
  • Fair-usage controls and secure access keys
POST /v1/verify/batch

# authenticate & submit references

POST /v1/verify/batch

Authorization: Bearer gw_live_••••

{ "refs": ["GW-D-9XF2K8QR", "GW-D-4M7Q2KXP"] }

# → 200 OK

[{ "ref": "GW-D-9XF2K8QR", "status": "active",

  "version": "STD-1.0", "review_due": "2027-08-16"},

{ "ref": "GW-D-4M7Q2KXP", "status": "not_found" }]

Portfolio intelligence

See what’s current - and what’s lapsing.

Across a book of insured sites, see at a glance which readiness documents are active, which are due for review, and which are missing.

A live signal that supports renewal and underwriting conversations.

Book readiness - live status412 sites
378
Active
29
Review due
5
Missing
GW-S-000417Hawkhills EstateActive
GW-S-000912Northgate RetailActive
GW-S-000688Thirsk LeisureReview due
GW-S-001240Riverside EventsNo document
How the access works

One layer to verify - nothing sensitive to hold.

Your platform already holds what it needs. GroundWork sits beside it: sensitive premises data stays in the site's client-side vault, and only a non-sensitive verification layer is ever exposed - to you, through the API or an agent.

The separation, by design

Sensitive information never reaches the verification layer. A site's locations, procedures and layout live only in their own browser - the client-side vault. They are never transmitted, so they're never in the path of anything you query.

The API and MCP layer exposes only the non-sensitive verification data - genuine, status, version, dates. That single layer serves every consumer: an insurer, a lender, or the site's own customer, each verifying by consent.

You get certainty without inheriting risk - there is no sensitive dataset to receive, secure, or govern on your side.

What you don't take on

Certainty by access - not another system to run.

Verification is a query, not a platform. There's no dashboard to adopt, no data to warehouse, and no new supplier for your teams to manage. You pull a genuine/current answer into the systems you already use - and everything that usually comes with a new data source simply doesn't apply.

Yet another SaaS dashboard to log into
Bulk data exports to store and secure
A fresh vendor procurement & due-diligence cycle
Sensitive data expanding your security surface
IT integration overhead for a heavy platform
Ongoing data-governance obligations
Just the answer you need - genuine, current, by consent - where you already work.
Who benefits, and how

A protective-security readiness signal, across your divisions.

The same verified signal - is a premises' readiness genuine, current, or missing - serves very different teams. Each can decide how to use it, from a single check to portfolio-wide monitoring.

Insurance & broking

A risk signal for underwriting and renewals

Which teams benefit

The same signal lands differently across the business:

UnderwritingRisk & actuarialClaimsPortfolio & exposureBroking & advisoryAccount management
How it can be used
  • Underwriting and new-business risk assessment
  • Renewal and mid-term review triggers
  • Premium and risk-rating inputs
  • Portfolio exposure and accumulation monitoring
  • Claims-readiness and duty-of-care evidence
  • Broker advisory and client-servicing prompts
Edge cases it covers

Beyond a simple check, the signal is useful precisely at the edges: a site whose document has lapsed since binding, a book with missing documents concentrated in one sector, or a superseded version presented as current at renewal. Absence is as informative as presence.

Finance & lending

A risk indicator for property portfolios

Which teams benefit

A protective-security readiness indicator is relevant right across a commercial lender:

Credit riskProperty riskESG & resiliencePortfolio managementInsuranceRelationship managers
How it can be used
  • Due diligence at origination
  • Annual reviews
  • Covenant monitoring
  • Insurance reviews
  • Property risk assessments
  • Relationship-management prompts
  • Enhanced credit-risk assessment
Edge cases it covers

The lender decides what the signal means for them. A missing document across secured properties may prompt a covenant conversation; a wave of reviews due can feed an annual-review cycle; and readiness status can sit alongside insurance and ESG data as one more resilience indicator on the book.

Documentation

Parse what you need - and route it where it's useful.

The verification response is structured, so you can extract exactly the fields a given team needs - and turn technical status into human-readable prompts for non-technical departments.

From one response, many uses

Our documentation will show how to:

  • Extract and parse specific fields - status, version, review dates
  • Batch-check a whole portfolio and flag what’s lapsing
  • Generate compliance review reminders, in bulk, by email
  • Turn status into plain-language summaries for non-technical teams
  • Route the right signal to the right division automatically

For example, a batch response can be filtered to just the properties a relationship manager needs to act on - no code required at their end, just a clear email.

DOCUMENTATION COMING SOON
Bring your own agent

BYOA - point your own agent at our verification layer.

Your agent, our layer

Bring the agent you already trust. Whatever automates your underwriting, portfolio or compliance work can call GroundWork's verification endpoint over MCP and get back a clean, non-sensitive answer - genuine, status, version, review date.

It docks, checks, and reports back. Your agent connects, verifies one document or a whole book, and returns the result into your own workflow. Nothing sensitive crosses over, because there's nothing sensitive to cross.

No lock-in, no new client to adopt - just your agent, speaking to our layer.

MCP-nativeAny agent frameworkBatch or singleNon-sensitive only

Prefer no integration?

Upload a file, download the results

Export your list of document references, upload it through a secure page, and download a results file showing the status of each - a whole book validated at once, no technical integration required.

The data position

You get certainty, not liability.

The reason this is safe to share is that there's nothing sensitive to share. GroundWork never stores a site's layout, procedures or vulnerabilities - those stay in the site's own document, on their own device. We hold only a non-sensitive index that confirms a document exists, whose it is, and when it was made.

  • No premises layouts, procedures, or locations - ever received or returned
  • Validation returns only non-sensitive status and identity, for matching
  • Access only where the site has chosen to share its reference with you
  • We do not sell data, and because sensitive data is not stored, none of it can be used to train AI models

Let's talk.

The portfolio and developer service is in active development. If you work in insurance, compliance, finance or programmatic verification, we'd like to hear how it could support your team.

Talk to us