Everything You Need to Know when Running a Factory
100 questions answered for owners, CEOs, and CFOs of US manufacturers serving the construction industry — on how to close the 6× → 12× EBITDA gap between hardware-only operations and vertically integrated platforms.
Filter by category or search any question instantly.
Security & Data
01Who owns our data in ConTech?
You own your data entirely. ConTech does not use customer data to train general-purpose models shared with other customers. Your historical quotes, pricing data, product catalog, and business documents remain your property and are isolated to your ConTech environment. We process your data to provide the service you've contracted for — and for nothing else. Data deletion requests are fulfilled within 30 days of contract termination. We maintain a data processing agreement (DPA) for all customers, available on request.
02How secure is ConTech for sensitive business data?
ConTech is SOC 2 Type II certified, which means an independent auditor has verified our security controls for data availability, confidentiality, and integrity. Our infrastructure runs on AWS with encryption at rest (AES-256) and in transit (TLS 1.3). Access to customer data within our organization is limited to authorized personnel on a need-to-know basis with full audit logging. We perform quarterly penetration testing and annual security audits. For customers with specific compliance requirements (ITAR, CMMC, HIPAA adjacent), we offer dedicated environment deployments with additional controls. Security documentation is available for customer review as part of the procurement process.
03Is our proprietary pricing and manufacturing data at risk?
No. Your pricing rules, cost data, and manufacturing specifications are stored in an isolated customer environment and are not accessible to other customers or to ConTech staff without your explicit authorization. The AI models we use are called via API from major providers (OpenAI, Anthropic, Google); these API calls do not include your customer-specific training data — only the specific context needed to process each request. We maintain a zero-retention agreement with our AI providers, meaning request content is not stored or used for model training by those providers.
04Does ConTech comply with GDPR?
Yes. ConTech is fully GDPR-compliant for processing EU personal data. Our platform is designed to minimize personal data collection — the focus is on business documents and transactional data, not personal information. For customers with EU operations or EU-based employees whose data flows through the platform, we provide: a Data Processing Agreement (DPA) on request, documentation of our sub-processors (AWS, OpenAI API with data processing agreements in place), and support for subject access requests and data deletion requests. Our legal entity and data processing structure is documented in our Privacy Policy.
05Can ConTech be deployed on-premise for security-sensitive manufacturers?
Yes. For manufacturers with classified work (ITAR/EAR), CMMC compliance requirements, or strict IT policies against cloud data processing, we offer an on-premise deployment option. In this configuration, the ConTech platform runs entirely within your network — no data leaves your environment. The on-premise deployment requires your IT team to provision a Linux server meeting our minimum specifications and perform the initial installation with our support. Ongoing updates are delivered as signed update packages. On-premise deployments have additional pricing and a longer implementation timeline; contact our enterprise team for specifics.
06Who within ConTech has access to our data?
Access to customer data within ConTech is governed by our internal access control policy. Support and customer success staff have access to configuration data (what workflows are set up, what integrations are connected) but not to your actual business documents or pricing data unless you explicitly share a specific file or record during a support session. Engineering staff access your data only when troubleshooting a specific issue that you've reported, with your authorization, and with full audit logging. We do not perform data mining, competitive analysis, or any commercial use of your data beyond service delivery.
07How does ConTech handle data residency requirements?
ConTech's primary infrastructure runs in AWS US-East (Virginia) and US-West (Oregon). For customers with data residency requirements in the EU, we offer an EU deployment on AWS EU-Central (Frankfurt). Canadian data residency on AWS Canada-Central (Montreal) is also available. Data residency configuration is set at account creation and cannot be changed post-deployment without migration assistance. If your data residency requirements are more specific (specific cloud provider, specific availability zone), contact our enterprise team — we support custom deployments for contracts above a specific annual value.
08What happens to our data if we stop using ConTech?
Upon contract termination, you have 30 days to export all your data via the self-serve data export feature (available in account settings). The export includes: all AI-generated outputs (quotes, documents, reports), all uploaded source files, all configuration data (workflow settings, pricing rules, integration configurations), and all audit logs. After the export period, your data is permanently deleted from our systems within 15 business days. We provide a written data deletion confirmation upon request. We do not retain any customer data after the deletion process is complete.
09How is customer data handled in PE due diligence reviews of our company?
If your company is undergoing a PE transaction — buy-side or sell-side due diligence — your platform data and ConTech configuration are your assets, not ours. We support due diligence processes by providing platform documentation packages on request: architecture diagrams, integration maps, data governance documentation, and SLA records that satisfy technology due diligence checklists from PE firms and their advisors. The platform data itself — your NRR metrics, dealer engagement records, order history, and configuration analytics — is available in export format for inclusion in your data room. We have supported 10+ customers through PE due diligence reviews and understand the documentation standards those processes require. Your data stays in your control throughout; we provide the documentation layer.