Esc

↑↓ move↵ openIndex · Pagefind
Security

Trust is a feature. We'll earn it in the open.

os.construction is pre-launch. Here is how we're designing the platform, what we use to run this website today and what we will not claim until it's true.

CertificationsWe do not hold SOC 2, ISO 27001 or any other security certification today. When we complete an audit or certification, we'll announce it here with the report details. Until then, we make no such claims.
Principles

How we're building it.

Data ownership & export

Your company owns its data. The product is being designed so you can export your records in standard formats, and leaving should never mean losing your history.

Roles & permissions

Access is designed so a sub sees their scope, a PM sees their projects, a controller sees the books. Permissions are part of the data model, not an afterthought.

Audit trail

Every change to a record is designed to keep who made it, when and what changed. That matters for COs, pay apps and lien waivers, and it matters for agents.

Human approval for agent actions

AI agents prepare work; people approve it. In the product, an agent will not be able to send money, submit a pay app or change a contract value without an authorized person signing off.

Encryption in transit

This website and its forms are served only over HTTPS (TLS). The product will follow the same rule for every connection.

Least privilege

People, services and agents get the minimum access they need. Internal access to customer data will be limited and logged.

Vendors

What runs this website today.

These are the third parties that process data for os.construction right now. We'll update this list when it changes, and publish the product's list before launch.

VendorPurposeWhat it touches
VercelWebsite hosting and serverless functionsServes every page and runs our form and AI-answer endpoints.
Vercel BlobStorage for form submissionsWaitlist, founding applications and contact messages are stored as private objects.
Google Analytics (GA4)Website analyticsAggregate usage: pages viewed, sign-up events. Reporting is enabled only on the production domain.
AnthropicAI answers on the websiteQuestions typed into “Ask the OS” are sent to Anthropic’s API to generate an answer.
ResendTransactional emailSends the confirmation email after you join the list.

Found a vulnerability or have a question?

Email hello@os.construction with details. Please don't publicly disclose an issue before we've had a chance to fix it. See also our privacy notice.

Contact us