Security · Trust · Compliance

Your project data is yours —
we just hold it for you

Your acceptance records, contracts, unit prices and site photos are your company's assets. This page sets out how we protect them, who can access them, and how you get them back if you decide to stop.

  • Data ownership stays with the customer
  • Everything can be exported when the contract ends
  • The audit trail cannot be deleted
The certification section is awaiting official content

The page structure follows the 7-block Trust Layer in the document. However, these items still need a statement with legal force — certifications, SLA commitments, data processing terms — must come from legal and engineering; they must not be written speculatively.

Still to add: certifications held (ISO 27001 / SOC 2 if any) · server location · data retention and deletion policy · uptime commitment · incident handling procedure · Terms of Use and Privacy Policy content.

Seven layers of assurance

This is the Trust Layer strip that appears at the foot of every page on the website — below is the full content of each layer.

Security — data protection
  • Data encrypted in transit and at rest
  • Permissions by role and by project
  • Multi-factor authentication for administrator accounts
  • Regular backups, with restore testing
Pending: specific encryption standards, backup cycle
Data Ownership
  • All business data belongs to your company
  • ERPCons does not use your data for any other purpose
  • Everything can be exported in a readable format
  • Data deleted on request when the contract ends
Pending: export terms, deletion deadline
Audit Trail
  • Records who created, edited, approved or deleted — and when
  • Document version history is never overwritten
  • The audit trail cannot be edited by users
  • Logs can be exported for independent audit
Pending: log retention period
Compliance
  • Compliant with Vietnamese data regulations
  • Record support for final settlement and audit requirements
  • Acceptance forms to current standards
Pending: list of certifications held, legal references cited
Integration & API — open connectivity
  • APIs to connect ERP, accounting, HR and equipment
  • Your data is not locked into a proprietary format
  • Technical documentation for the customer's IT team
Pending: link to public API documentation
Implementation
  • Discovery and configuration against your real process
  • Migrate data from the old system
  • Role-based training, with documentation you keep
  • Support through the first phase of operation
Pending: committed duration per package
Support & SLA
  • Support channels by incident priority
  • Contractual response-time commitments
  • Proactive notice of system maintenance
Pending: SLA table, uptime commitment
Does your IT team have deeper questions?

We have a technical pack your IT department can review.

Request the technical pack

How data goes in and comes out

The most important question when evaluating a platform is not “is the data safe”, but “what if I want to stop”. We answer them up front.

A platform that holds your data hostage is a platform you should not choose.
Feed intoImport from the old system, from Excel, or through an API
While you use itRole-based permissions, encryption, audit logging
ExportExport any time in a readable format, with no dependency on ERPCons
FinishHand over all data, then delete it on request
Written into the contract, not just on a website

Commitments on data ownership, export and deletion are written into the contract terms. This page is only a summary — the contract is the legal basis.

Trust Layer
A trusted platform for sustainable operations

Security — Transparency — Compliance — Ready to scale

SecurityMulti-layer data security
Data OwnershipData ownership
Audit TrailA complete audit trail
ComplianceLegal compliance
Integration & APIOpen, flexible connectivity
ImplementationImplementation & Training
Support & SLASupport & Commitment

Does your IT team need a deeper review?

We are happy to work directly with your IT and legal teams.