Security whitepaper · version 1.2 · 3 September 2026

What is built,
and how it is operated.

Engineering Root Solutions (ERS) · Commercial Registration 7054208009 · Kingdom of Saudi Arabia. Applies to build r200 and later. This document is public and is maintained with the product: its claims are checked against the internal Statement of Applicability at each quarterly audit, and the version and date above change whenever a statement changes.

1 · In one paragraph

Engineering Workspace is a desktop application for engineering correspondence, deliverables and design-workflow control. It installs on your own Windows PC or Mac and keeps everything — documents, the search index, the database, the audit trail — on that machine. ERS operates no service that receives your documents. Sign-in is always required, roles are enforced by the server, administrators of a shared workspace use two-factor authentication, secrets are encrypted per user, and every update and licence key is cryptographically signed and checked offline. ERS runs a structured information security programme built on the controls of ISO/IEC 27001:2022. This document says what is built and how it is operated.

2 · Where your data lives

On the machine you run it on.

ItemLocationNotes
Your documentsThe folders you already keep, indexed in placeNothing is copied or uploaded
Index, OCR text, database, deliverables, journalsThe data folder you choose at first run — a local disk or an external SSDBacked up by the app's own job to a second folder you choose
Accounts, roles, per-user secrets, audit trailThe application database on the same machineSecrets encrypted per user
BackupsA second folder you chooseIncremental; live databases are snapshotted safely
ERS's sideNothing of the aboveOnly the small records in section 4

The application listens on the machine's loopback address only. Reaching it from another computer requires either your own network arrangements or the built-in remote-access option (section 6).

3 · What runs locally

Everything that touches your documents.

Indexing, OCR, embedding, search, the registers, the instant outbound check, the calculators, the studios, the workflow engine and the audit trail run on your machine with bundled components. The installers are large precisely because they carry everything — both search-quality tiers, the readers, the drawing converter and OCR — so that setup needs no downloads and daily use needs no connection.

4 · What can leave the machine

The complete list.

Nothing in this table is on unless you or the licence say so. There is no telemetry.

ConnectionWhenWhat is sentWho receives it
Update checkWhen an administrator presses “Check for updates” in Settings (Store installs update through the Store)A plain request for a small version file; nothing about youengspace.app
Licence check-inDaily, for managed licencesApplication version, a machine code, document counts — never contentERS
AI providerOnly after you paste your own provider key in Settings, and only for the task you runThe question and the passages or documents chosen for that task, under your own account and termsThe provider you chose
Mail, calendar, notesOnly when you sign in or connect a local readerRead into the workspace; only a message you explicitly send leaves your own mailboxYour own mail platform
Project platformsOnly when you sign inRead into the workspaceThe platform you chose
A register’s linked fileOnly when a register is linked to a SharePoint or OneDrive linkA read-only request for that one file, under the linking person’s own Microsoft sign-in; nothing is written backMicrosoft
Workflow noticesOff by default; your own mail relay“Your action is waiting” notices, never correspondenceYour relay
Phone pushOff by defaultNotification titles onlyThe push topic you chose
Remote accessOnly after an administrator switches it on, on a machine that has the tunnel clientYour own sessions, over TLSThe edge provider and your users
Downloading the appOnceA standard download requestengspace.app / the Store

Before each release the list of outbound endpoints in the code is compared with this table; a new one is added here in the same release.

5 · Identity, access and roles

Enforced by the server, tested as every role.

ControlWhat it means for you
Sign-in always requiredIncluding on the machine itself; there is no local bypass
PasswordsHashed with Argon2id; never logged; a minimum length is enforced
Brute forceSign-in is rate-limited per address and account with progressive lockout; failures are alerted to administrators
Two-factorAdministrators of a shared workspace (a company licence, a network address or remote access) must enrol an authenticator app before their first session; with remote access on, every user does, and a company can require it for everyone regardless. On one computer it is optional
Roles enforced by the serverOwner, admin, engineer, viewer, client, management. A client or management sign-in reaches the progress portal and nothing else — enforced in the API, not hidden in the interface
Elevated actionsInstalling updates, managing users and destructive actions ask for a fresh re-authentication
SessionsSigned, time-limited cookies (httpOnly, SameSite, Secure over HTTPS); a network session ends after a period of inactivity and never outlives its sign-in; changing a user's password or deactivating them revokes every session
Cross-site protectionState-changing requests are checked against their origin
Per-user secretsMail sign-ins and provider keys are encrypted per person; no user and no API can read another's
The operator's own machineMail, calendar and notes read from the computer the workspace runs on belong to the owner, not to the administrator role
Audit trailLogins, changes, approvals, substitutions, escalations and deletions, with who and when
SeatsA personal key holds one seat; a company key counts its seats, with portal accounts free

Before each release, the whole route table is exercised as every role by an automated test, and the product is walked in a browser as each role; a route that answers a role it should not is a defect and is fixed before shipping.

6 · Remote access for teams

Outbound only, with an allow-list in front.

A company can reach one workspace from other computers through an outbound-only tunnel: the application never opens an inbound port; the tunnel client connects out over TLS and the edge presents a real certificate. The recommended set-up adds an edge allow-list of e-mail addresses in front of the sign-in page. Remote access is a deliberate choice: it is off until an administrator switches it on in Settings, it needs the tunnel client on the machine (the installers do not include it), and while it is on every user enrols an authenticator app. Switching it off closes the link at once.

7 · Integrity of what we ship

Signed, or checksummed — and verifiable.

ArtefactProtectionStatus
Microsoft Store packageSigned by Microsoft; installed and updated by the StoreLive
In-app update packagesEd25519 signature over the package digest, verified before installation; a tampered package refuses itselfLive
Licence keysEd25519-signed payloads verified offline; a forged key does not verifyLive
Website installersServed over HTTPS; SHA-256 checksums published on the download page, in SHA256SUMS.txt and in checksums.jsonLive
Code-signing certificates for the website installersApple notarisation, and a Windows certificate that puts our verified name on the install dialog. Windows shows a SmartScreen notice for any installer it has not seen enough times, signed or not, so the Store remains the route with no notice at allIn progress — every installer ships with a published SHA-256 in the meantime
DependenciesPinned; audited against public vulnerability databases before every releaseLive
8 · Backups and continuity

Nothing is ever disabled or deleted remotely.

The app's own backup job copies everything that cannot be regenerated — the database (through a safe snapshot), settings, journals — plus the index and deliverables to a second folder you choose, incrementally. Your documents are your own folders and are not copied by the job; mirror them as you already do.

If a licence expires, the workspace turns read-only after a grace window and every document stays where it was. If the licence service is unreachable, the application keeps working. If ERS ceased to exist, you would keep the software you have, indefinitely. A tool used on a live site must never brick itself mid-project — that is a design rule.

9 · ERS's own security programme

Built on ISO/IEC 27001:2022.

ERS runs a structured information security management system built on the controls of ISO/IEC 27001:2022: a defined scope, a policy, a risk methodology and a living risk register, a Statement of Applicability covering all 93 Annex A controls, operating procedures for development and release, access control and cryptography, incident response, suppliers, continuity and assets, and a quarterly internal audit with a corrective-action log. The programme is maintained with the product, and its documents are available to customers under NDA.

At every releaseA dependency audit of both installer payloads against public vulnerability databases; a secret scan of the repository and release tooling; the role and position tests; a static verification of the packages; a review of every outbound connection against section 4.
The first full cycle — September 2026Sign-in, sessions, cross-site protection, rate limiting and file handling, the mail-domain authentication records and the download endpoints were reviewed; everything the cycle touched is recorded in the product's change ledger.
NextApple notarisation and a Windows code-signing certificate for the direct installers, and the next internal audit in December 2026. This section is updated as each lands.
On request, under NDAThe Statement of Applicability, the policy, the architecture and data-location pack, the backup and restore runbook, the update-signing design, and a review call with the person who built it.
10 · Shared responsibility

Who does what.

ERS is responsible forYou are responsible for
The product's controls in sections 5–8 and their testingChoosing and protecting the data folder and the backup destination (disk encryption, physical security)
Signing and verifying what we shipInstalling from the Store or verifying the checksum of a website installer
Answering security reports and shipping fixesKeeping the operating system current; installing updates when offered
Never receiving your documentsDeciding whether to connect an AI provider, mail or project platform, and under whose terms
The confidentiality of the few records we hold about youManaging your users: strong passwords, prompt deactivation, the edge allow-list if you use remote access
Saying plainly what is doneTelling us when something looks wrong
11 · For your IT department

The short answers.

12 · Reporting a vulnerability

Write to us. We answer within two working days.

Write to [email protected]. We acknowledge within two working days, keep you informed, fix in order of severity, and credit you in the release note if you wish. Good-faith research on your own or a trial installation is welcome; please do not test other people's installations, do not access data that is not yours, and give us reasonable time to fix before publishing. We will not pursue anyone who follows these rules. The machine-readable contact is at https://engspace.app/.well-known/security.txt.

← Security & architectureDownload →