Engineering Root Solutions (ERS) · Commercial Registration 7054208009 · Kingdom of Saudi Arabia. Applies to build r200 and later. This document is public and is maintained with the product: its claims are checked against the internal Statement of Applicability at each quarterly audit, and the version and date above change whenever a statement changes.
Engineering Workspace is a desktop application for engineering correspondence, deliverables and design-workflow control. It installs on your own Windows PC or Mac and keeps everything — documents, the search index, the database, the audit trail — on that machine. ERS operates no service that receives your documents. Sign-in is always required, roles are enforced by the server, administrators of a shared workspace use two-factor authentication, secrets are encrypted per user, and every update and licence key is cryptographically signed and checked offline. ERS runs a structured information security programme built on the controls of ISO/IEC 27001:2022. This document says what is built and how it is operated.
| Item | Location | Notes |
|---|---|---|
| Your documents | The folders you already keep, indexed in place | Nothing is copied or uploaded |
| Index, OCR text, database, deliverables, journals | The data folder you choose at first run — a local disk or an external SSD | Backed up by the app's own job to a second folder you choose |
| Accounts, roles, per-user secrets, audit trail | The application database on the same machine | Secrets encrypted per user |
| Backups | A second folder you choose | Incremental; live databases are snapshotted safely |
| ERS's side | Nothing of the above | Only the small records in section 4 |
The application listens on the machine's loopback address only. Reaching it from another computer requires either your own network arrangements or the built-in remote-access option (section 6).
Indexing, OCR, embedding, search, the registers, the instant outbound check, the calculators, the studios, the workflow engine and the audit trail run on your machine with bundled components. The installers are large precisely because they carry everything — both search-quality tiers, the readers, the drawing converter and OCR — so that setup needs no downloads and daily use needs no connection.
Nothing in this table is on unless you or the licence say so. There is no telemetry.
| Connection | When | What is sent | Who receives it |
|---|---|---|---|
| Update check | When an administrator presses “Check for updates” in Settings (Store installs update through the Store) | A plain request for a small version file; nothing about you | engspace.app |
| Licence check-in | Daily, for managed licences | Application version, a machine code, document counts — never content | ERS |
| AI provider | Only after you paste your own provider key in Settings, and only for the task you run | The question and the passages or documents chosen for that task, under your own account and terms | The provider you chose |
| Mail, calendar, notes | Only when you sign in or connect a local reader | Read into the workspace; only a message you explicitly send leaves your own mailbox | Your own mail platform |
| Project platforms | Only when you sign in | Read into the workspace | The platform you chose |
| A register’s linked file | Only when a register is linked to a SharePoint or OneDrive link | A read-only request for that one file, under the linking person’s own Microsoft sign-in; nothing is written back | Microsoft |
| Workflow notices | Off by default; your own mail relay | “Your action is waiting” notices, never correspondence | Your relay |
| Phone push | Off by default | Notification titles only | The push topic you chose |
| Remote access | Only after an administrator switches it on, on a machine that has the tunnel client | Your own sessions, over TLS | The edge provider and your users |
| Downloading the app | Once | A standard download request | engspace.app / the Store |
Before each release the list of outbound endpoints in the code is compared with this table; a new one is added here in the same release.
| Control | What it means for you |
|---|---|
| Sign-in always required | Including on the machine itself; there is no local bypass |
| Passwords | Hashed with Argon2id; never logged; a minimum length is enforced |
| Brute force | Sign-in is rate-limited per address and account with progressive lockout; failures are alerted to administrators |
| Two-factor | Administrators of a shared workspace (a company licence, a network address or remote access) must enrol an authenticator app before their first session; with remote access on, every user does, and a company can require it for everyone regardless. On one computer it is optional |
| Roles enforced by the server | Owner, admin, engineer, viewer, client, management. A client or management sign-in reaches the progress portal and nothing else — enforced in the API, not hidden in the interface |
| Elevated actions | Installing updates, managing users and destructive actions ask for a fresh re-authentication |
| Sessions | Signed, time-limited cookies (httpOnly, SameSite, Secure over HTTPS); a network session ends after a period of inactivity and never outlives its sign-in; changing a user's password or deactivating them revokes every session |
| Cross-site protection | State-changing requests are checked against their origin |
| Per-user secrets | Mail sign-ins and provider keys are encrypted per person; no user and no API can read another's |
| The operator's own machine | Mail, calendar and notes read from the computer the workspace runs on belong to the owner, not to the administrator role |
| Audit trail | Logins, changes, approvals, substitutions, escalations and deletions, with who and when |
| Seats | A personal key holds one seat; a company key counts its seats, with portal accounts free |
Before each release, the whole route table is exercised as every role by an automated test, and the product is walked in a browser as each role; a route that answers a role it should not is a defect and is fixed before shipping.
A company can reach one workspace from other computers through an outbound-only tunnel: the application never opens an inbound port; the tunnel client connects out over TLS and the edge presents a real certificate. The recommended set-up adds an edge allow-list of e-mail addresses in front of the sign-in page. Remote access is a deliberate choice: it is off until an administrator switches it on in Settings, it needs the tunnel client on the machine (the installers do not include it), and while it is on every user enrols an authenticator app. Switching it off closes the link at once.
| Artefact | Protection | Status |
|---|---|---|
| Microsoft Store package | Signed by Microsoft; installed and updated by the Store | Live |
| In-app update packages | Ed25519 signature over the package digest, verified before installation; a tampered package refuses itself | Live |
| Licence keys | Ed25519-signed payloads verified offline; a forged key does not verify | Live |
| Website installers | Served over HTTPS; SHA-256 checksums published on the download page, in SHA256SUMS.txt and in checksums.json | Live |
| Code-signing certificates for the website installers | Apple notarisation, and a Windows certificate that puts our verified name on the install dialog. Windows shows a SmartScreen notice for any installer it has not seen enough times, signed or not, so the Store remains the route with no notice at all | In progress — every installer ships with a published SHA-256 in the meantime |
| Dependencies | Pinned; audited against public vulnerability databases before every release | Live |
The app's own backup job copies everything that cannot be regenerated — the database (through a safe snapshot), settings, journals — plus the index and deliverables to a second folder you choose, incrementally. Your documents are your own folders and are not copied by the job; mirror them as you already do.
If a licence expires, the workspace turns read-only after a grace window and every document stays where it was. If the licence service is unreachable, the application keeps working. If ERS ceased to exist, you would keep the software you have, indefinitely. A tool used on a live site must never brick itself mid-project — that is a design rule.
ERS runs a structured information security management system built on the controls of ISO/IEC 27001:2022: a defined scope, a policy, a risk methodology and a living risk register, a Statement of Applicability covering all 93 Annex A controls, operating procedures for development and release, access control and cryptography, incident response, suppliers, continuity and assets, and a quarterly internal audit with a corrective-action log. The programme is maintained with the product, and its documents are available to customers under NDA.
| ERS is responsible for | You are responsible for |
|---|---|
| The product's controls in sections 5–8 and their testing | Choosing and protecting the data folder and the backup destination (disk encryption, physical security) |
| Signing and verifying what we ship | Installing from the Store or verifying the checksum of a website installer |
| Answering security reports and shipping fixes | Keeping the operating system current; installing updates when offered |
| Never receiving your documents | Deciding whether to connect an AI provider, mail or project platform, and under whose terms |
| The confidentiality of the few records we hold about you | Managing your users: strong passwords, prompt deactivation, the edge allow-list if you use remote access |
| Saying plainly what is done | Telling us when something looks wrong |
Write to [email protected]. We acknowledge within two working days,
keep you informed, fix in order of severity, and credit you in the release note if you wish. Good-faith research on
your own or a trial installation is welcome; please do not test other people's installations, do not access data
that is not yours, and give us reasonable time to fix before publishing. We will not pursue anyone who follows these
rules. The machine-readable contact is at https://engspace.app/.well-known/security.txt.