Skip to main content

Security & AI Trust

A safe, trusted ecosystem for contractors.

The Construction Leadership Network has run contractor peer groups since 1987. AIRE Assessment™ and the Construction Technology & AI Road Map carry that trust into the AI era: plain rules, no surprises, and a people layer that teaches every work style the one security habit it is best placed to own.

What we hold

A name, an email, a job title and 41 answers. No payroll, no performance data, no company financials. Results are a developmental work-style profile, never a score used to rank or dismiss anyone.

Where it lives

In a managed Postgres database with row-level security, so an account reads only its own records and an employer sees only the seats it paid for. Data is encrypted in transit (TLS) and at rest. Payments run through Stripe; card numbers never touch our servers.

Who can see it

The person who took the assessment, the employer or educator who issued the seat, and named operators for support. No advertising, no resale, no training of third-party AI models on your answers.

Deleting it

Email info@constructionleaders.org with the subject line "Delete my AIRE data" and the account is removed. We acknowledge within two business days.

Reporting a problem

If you believe you have found a security issue, email info@constructionleaders.org with the subject line "Security". Please give us a chance to respond before disclosing publicly. Machine-readable contact: /.well-known/security.txt.

Not SOC 2 certified. We state what is in place, not what is planned.

One security habit per AIRE type

Security fails at the people layer, not the firewall. Each of The AIRE Nine™ gets the one learning objective that fits how that type already works. Content only; nothing here changes anyone's result.

  1. 1
    AIRE Pilot

    Approve a new AI tool only after the vendor's data-use terms are read

    Pilots move first and bring tools in. Speed is the strength and the exposure.

    The practice: Before turning on any AI feature, get written answers to the six vendor questions: is our data used to train your models, where is it stored, who at your company can see it, how long is it kept, how do we delete it, what happens at contract end.

  2. 2
    AIRE Architect

    Put one system of record per function and name where sensitive data lives

    Architects design the stack. Data classification is a design decision, not an IT chore.

    The practice: Keep a one-page map: bids, payroll, owner contracts, employee data, each with its system of record and who has access. No sensitive data in personal drives or text threads.

  3. 3
    AIRE Analyst

    Check what leaves the building when data goes into a model

    Analysts feed AI the most data. The prompt is an export.

    The practice: Strip names, account numbers and contract terms before pasting into any tool not on the approved list; use the company workspace, never a personal login.

  4. 4
    AIRE Operator

    Run the payment-change callback rule without exception

    Operators execute. Wire fraud lands on the person who processes the change.

    The practice: Any change to a vendor's bank details, or any wire request, is confirmed by a phone call to a number already on file, and never by replying to the email that asked. Two people sign off.

  5. 5
    AIRE Steward

    Own the one-page incident plan and the access review

    Stewards protect people and process. When someone leaves, the Steward closes the door.

    The practice: Same-day access removal when people join, move or leave; a printed incident sheet with IT, bank, insurer and counsel numbers; a quarterly check that MFA is on every mailbox.

  6. 6
    AIRE Translator

    Teach the two phishing patterns that actually hit contractors

    Translators carry the message to the field and the office. Awareness that sticks is a translation job.

    The practice: Fifteen minutes at the office meeting: the spoofed-vendor bank change and the fake executive urgent wire. Repeat quarterly, with the newest real example.

  7. 7
    AIRE Builder

    Build automations that never store a credential in the open

    Builders wire tools together. Secrets in a spreadsheet or a shared prompt are the common leak.

    The practice: API keys and passwords live in the platform's secret store; every integration into accounting or the PM platform is on the third-party access list with an expiry date.

  8. 8
    AIRE Verifier

    Ask the six vendor-AI data questions and keep the answers

    Verifiers are the skeptics. This is the room where their instinct pays the company back.

    The practice: Own the vendor question sheet; refuse any purchase that cannot answer all six; check renewal terms against the answers once a year.

  9. 9
    AIRE Pragmatist

    Keep the basics green: MFA, tested backups, endpoint protection

    Pragmatists keep what works working. The three controls that stop most losses are maintenance, not projects.

    The practice: Monthly: MFA on for every login, one restore actually tried this quarter, every laptop and phone on the managed agent with updates applied.

The six vendor-AI data questions

Ask them before any AI feature is switched on. Keep the answers with the contract.

  1. Is our data used to train your models, or anyone else's?
  2. Where is it stored, and in which country?
  3. Who at our company, and at yours, can see it?
  4. How long is it kept?
  5. How do we delete it, and how do we prove it is gone?
  6. What happens to it when the contract ends?

Coming January 26, 2027

CLN AI Security Essentials

A credential from the Construction Leadership Network, debuting at the CLN Annual Conference, Dallas. Built to the standard of the established entry-level security certificates: role-based training, a scenario assessment, and a renewal clock. It sits on the same badge rail as the AIRE Assessment™, so a contractor can show one verified page for both.

Company-level controls (wire-fraud verification, MFA, backups, AI acceptable use and nine more) are scored in every Road Map strategic plan at roadmapforai.com, Section 11.