Skip to content

How we handle your data

How we handle the records your business runs on.

You are sending dispatch exports, CRM records, job-costing data and financial files. This page explains where that data goes, who can see it, how client records are separated, and what never enters the benchmark pool.

These are the operational details. The privacy notice is the legal document.

Follow the data through the audit
The audit method / from source to finding
01Dispatch exports
02CRM and job records
03Job costs and invoices
04Accounting exports

Within the client engagement

  1. 01Organise the evidence
  2. 02Reconcile and analyse
  3. 03Review the findings
Your audit
  • Ranked findings
  • Margin Integrity Score
  • 90-day roadmap

A conceptual map of the practitioner-led audit. This is not a live connection, automatic upload or a record of client data.

Agreed exports, not bank logins. Ask what to remove before sending a file.

What we ask for

Four files, and the shortest version of each that answers the question.

Source file01

Dispatch or scheduling exports

What it answers
Where time goes, and where the board is stretched
What we do not need
Private notes unrelated to jobs
Source file02

CRM or customer and job records

What it answers
Whether calls became bookings, and bookings became work
What we do not need
Marketing lists, or anyone who was never a customer
Source file03

Job costing and invoices

What it answers
What the work actually cost against what it billed
What we do not need
Anything about an employee as a person
Source file04

The books, usually QuickBooks or Xero

What it answers
Whether the work turned into margin
What we do not need
Bank logins. We take an export, never a credential

If a file contains more than we asked for, say so before you send it and we will tell you what to strip. We would rather receive less.

Why all four

Read the four files together.

A busy dispatch board and a thin month in the books can both be accurate. Comparing them helps explain why the work did not turn into margin.

We ask for records covering a period rather than a single snapshot. Several months help distinguish seasonal changes from recurring patterns.

Follow one audit, step by step.

Explore the work from source files to reviewed findings. This illustrates the audit method and the checks the team performs; it does not represent an automated integration.

01

Receive the agreed exports

We agree which files and time period are needed before you send anything, including what to leave out. Send the smallest set of files that answers the audit questions.

What comes in
Dispatch, CRM, job-costing and accounting exports; interviews with the team.
What the team does
Confirm the sources and period needed. Exclude unrelated personal information and credentials.
What moves forward
The agreed evidence set.

Illustrative working record

An intake checklist

Source
Dispatch / CRM / job costs / books
Period
Agreed with the client
Leave out
Bank credentials and unrelated private information
Example structure only. No client records, completed checks or measured results are shown.
02

Organise the evidence

Before interpreting the numbers, we check that the files describe the same business at a comparable level of detail. We map the source fields and check that the records are complete.

What comes in
The agreed exports in their source formats.
What the team does
Map the fields, check completeness and align the records to a consistent level of detail.
What moves forward
An organised dataset with its source context.

Illustrative working record

From source fields to audit fields

Source field
Job reference in an export
Audit field
Comparable job reference
Context kept
Source file and reporting period
Example structure only. No client records, completed checks or measured results are shown.
03

Reconcile the accounts

Put operational records beside costs and invoices. Where the accounts disagree, the difference needs an explanation before it becomes a finding.

What comes in
Job activity, costing, invoices and the books.
What the team does
Compare the records and identify gaps or disagreements that need an explanation.
What moves forward
Reconciled evidence and questions that need review.

Illustrative working record

One job, viewed across sources

Operations
Was the work recorded?
Job costing
What cost was assigned?
Accounting
What was billed and recorded?
Review question
Do the records tell the same story?
Example structure only. No client records, completed checks or measured results are shown.
04

Analyse the four stages

Read booking, dispatch, pricing and retention together. A finding should connect a source to a metric and explain why it deserves attention.

What comes in
The reconciled evidence and stated benchmark basis.
What the team does
Compare the four stages and rank the recoverable opportunities.
What moves forward
Findings tied to the evidence behind them.

Illustrative working record

The anatomy of a finding

Stage
Booking / dispatch / pricing / retention
Evidence
Source records and comparison basis
Interpretation
What the gap means
Priority
Recoverable value and the next action
Example structure only. No client records, completed checks or measured results are shown.
05

Review the findings

The team reviews the extraction, benchmark comparison and financial interpretation before giving advice to the owner.

What comes in
Draft findings and the proposed priorities.
What the team does
Review extraction, benchmark matching, margin interpretation and the roadmap.
What moves forward
Reviewed findings with an explained priority order.

Illustrative working record

A review checklist

Data review
Does the extraction support the metric?
Benchmark review
Does the comparison fit?
Financial review
Does the margin interpretation hold?
Roadmap review
Is the next action justified?
Example structure only. No client records, completed checks or measured results are shown.
06

Deliver the audit

The result is an explanation your team can act on: where the gaps are, what supports the numbers and what to address first.

What comes in
The reviewed findings and priorities.
What the team does
Present the ranked findings, the score and the proposed sequence of work.
What moves forward
Your audit and a 90-day roadmap.

Illustrative working record

What reaches the owner

Findings
A ranked list with supporting evidence
Score
Margin Integrity Score and stage scores
Roadmap
Prioritised actions over 90 days
Example structure only. No client records, completed checks or measured results are shown.

Who can see it

Database rules restrict access to your organisation and its assigned team.

Organisation-scoped access

IdentityScope of access
OperatorThe organisations they are assigned to.
ClientTheir own company, and nothing else.
No identityNothing. An anonymous request reads no client work.

A re-run adds a new audit-artifact version and leaves the previous one in place.

Conceptual view of the operator, client and anonymous access described below; not a certification or test report.

Tables holding client work are scoped to one organisation. The database enforces the access rules on the tables themselves. Operators see the organisations they are assigned to; clients see only their own company. Requests without an identity read nothing.

An isolation suite checks this with real operator, client and anonymous sessions, counting what each can read. It runs on every check. The public site has no permission to read the tables that hold audit artifacts, so a request is refused rather than returning an empty result.

Audit artifacts are append-only. A re-run adds a version instead of overwriting the previous one. Nothing that has been recorded about your business can be quietly rewritten, including by us.

What is walled off from what

Client records and the benchmark pool stay separate.

Separate organisation boundaries

Organisation A

One client boundary

  • Client work
  • Audit artifacts
  • Model-call records

Organisation B

A separate client boundary

  • Client work
  • Audit artifacts
  • Model-call records

Aggregate records

The benchmark pool

Only de-identified aggregates from a delivered audit may enter, and only if you agree. Your files and findings stay out.

The organisation boundary applies from either side. The benchmark pool is not a shared store of client work.

Conceptual separation, not a diagram of physical infrastructure. Organisation A and B are illustrative labels, not clients.

The separation between clients applies in both directions. The benchmark pool is separate again, with a structure that can hold only aggregates.

What never enters the benchmark

Your name, your files and your findings are not benchmark records.

Excluded records and eligible aggregates

De-identified aggregates may enter only if you agree to it.

Outside the benchmark

No record that points back to you.

  • Your name
  • Your files
  • Your findings
  • Links to a company, contact or engagement

Eligible only under the benchmark rules

De-identified aggregates

  • Percentile bands
  • Grouped by trade, revenue band and region
  • Bands must not be traceable to one business

The estimator follows the same rule: its record has no email, contact or company.

Conceptual eligibility diagram. It shows categories of records, not a real audit or a populated benchmark.

The benchmark contains percentile bands grouped by trade, revenue band and region. Its table has no organisation or client column and no link to a company, contact or engagement. These restrictions are built into the table structure, and a build check fails if any of those fields appear.

The estimator on the home page follows the same rule. It records that the tool ran and what it returned, without an email, contact or company on the record.

De-identified aggregates from a delivered audit may enter only if you agree. A band that could only have come from one business is not eligible. The full rules are on the benchmark page.

Language models

How language models are used in the audit.

The record of a model call

Which steps use a model is still being settled. This page will name them when it is.

Input

Only what that step needs.

The required context from your own records and interviews, not your files wholesale.

Purpose

Summarise and help find the bottleneck.

The model does not produce the findings and does not invent numbers.

System prompt
Exact prompt
Context
Exact assembled context
Response
Exact returned text
Model
Which model answered
Cost
What the call cost

The full call record stays inside your tenant boundary and is readable by the delivery team, not by a public endpoint.

Conceptual record structure, not an actual prompt, output or completed model call.

We use models to summarise and help find bottlenecks. They do not produce findings or invent numbers. Their input comes from your CRM, operations software and interviews with your team. Which steps use a model is still being settled; this page will name them when that is decided. Three providers are configured: Anthropic, Google and OpenAI.

Only the input needed for a step goes to the model, not your files wholesale. Every call is recorded in full. The record includes the system prompt, assembled context and returned text exactly as they were sent or received, plus the model name and cost.

The record stays inside your tenant boundary and is readable only by the delivery team. No public endpoint can reach it; the isolation suite tests that on every check. If you want to know what was sent to a model about your business, we can refer to the exact record.

How long we keep it

One year from the close of the engagement, then it goes.

The retention policy

  1. 01 / The starting point

    Engagement closes

    The retention period starts here.

  2. 02 / The comparison window

    One year

    Your exports, audit artifacts and model-call records are held for a year after close.

  3. 03 / At the end

    Removal under the policy

    Write to us if you want removal sooner.

Exception: de-identified benchmark aggregates are retained because they carry no link back to your business.

Conceptual timeline of the stated retention policy, measured from engagement close. It does not depict an automated deletion system.

We keep your exports, the artifacts built from them and every model-call record for a year after the engagement closes, then remove them. That gives us a record to compare against if you have a re-audit twelve months later.

Write to us if you want earlier removal. De-identified benchmark aggregates are the exception: we keep them because they carry no link back to your business.

Where it lives, and who else touches it

One database, in Northern Virginia.

Hosting and model providers

Client-data store

One Postgres database

Hosted by Supabase · US East · Northern Virginia

  • No second store
  • No analytics or session recording on client-data surfaces

Configured model providers

Only the input a step needs.

Which audit steps use a model is still being settled.

  • Anthropic
  • Google
  • OpenAI

The page changes when the list of providers that could see client figures changes.

Conceptual map of the named data destinations, not a network topology or an additional security guarantee.

Client data is held in one Postgres database hosted by Supabase in the US East region, Northern Virginia. It is not copied to a second store. No analytics or session-recording tools run on the surfaces that hold it.

The model providers named above are the only third parties that see audit material, and they receive only the input needed for a given step. We update this page whenever that list changes, including a hosting provider, error monitor or any other service that could see a client's figures.

Before you send anything

Ask first. We would rather receive less.

If you are unsure whether a file contains more than we need, send the question rather than the file.