
Protect project files through design, delivery, and archive
Control access to project files, secure devices used on site, and define backup coverage for the systems your practice uses.
Or email hello@teclara.tech
Security risks
Review project access as collaborators and responsibilities change.
Consultants, trades, bidders, and clients need different access at each project stage. Review permissions at those transitions and remove external access when it is no longer required.
Design development
Consultants need project access
Structural, mechanical, and electrical consultants exchange files with the studio, often through share links or guest accounts. Named guest accounts and expiring links make access easier to track and review.
Tender
The drawing set goes out
Bid documents go to contractors the practice may never work with. Links created for a tender should expire when the tender closes.
Construction
Work moves to site
Laptops and tablets go to site meetings and come back with markups and photos. Managed devices stay encrypted and patched wherever they travel.
Closeout and archive
Archive project records
Project records are kept long after the building opens. Guest access is removed at closeout.
Security controls
Project access can outlast the project itself
Long projects and frequent external collaboration require regular access reviews.
Projects
Scope access to the project team
Where project folders live in Microsoft 365 or Google Workspace, access is limited to the assigned team. Permissions are reviewed when roles change or the project closes.
Sharing
Put limits on external links
Consultants and trades use named guest accounts or expiring links where supported. Regular reviews identify external access that is no longer needed.
Devices
Protect workstations and site laptops
The devices we manage receive managed endpoint protection, encryption, and security updates. The security team reviews alerts, investigates suspicious activity, and coordinates the response.
Sign-ins
Watch for account takeover
Multi-factor authentication, administrator controls, and sign-in monitoring help prevent unauthorized access using stolen credentials. The security team investigates suspicious sessions and inbox-rule changes under the agreed response process.
Email
Reduce invoice and payment fraud
Email controls filter phishing and impersonation attempts aimed at project accounting. The practice remains responsible for verifying payment changes through a trusted contact method.
Recovery
Define backup coverage for project files
We maintain independent backups of Microsoft 365 or Google Workspace data and test restores.
Security documentation
Maintain security records for clients, insurers, and principals.
Client agreements and insurance renewals may require evidence of security controls. Current access and backup records also help principals review how project information is protected.
- Institutional or public-sector client
- How are our drawings and building information protected, and who outside your firm can access them?
- The access model for project folders, the external sharing settings, and a current list of guests on that client’s projects.
- Cyber insurer, at renewal
- Is MFA enforced? Are backups separate and tested? Are devices protected?
- MFA coverage, device protection status, and the backup scope with the date of the last restore test, including what the backup does not cover.
- A principal, after a departure
- Which projects can they still open, and which links did they create?
- An offboarding record showing when account and device access was removed and active sessions were revoked, together with a report of sharing links created by the account.
Your responsibilities
The practice decides how long project records are kept and which contractual or professional requirements apply. Teclara operates the security controls we manage and documents what the backup covers. CAD, BIM, rendering files, workstations, NAS devices, servers, and project applications are included only when specified in the service agreement.
Managed Security & Compliance
Ongoing security for your accounts, devices, and data.
The security controls on this page run on the platform you use, with access controls, reporting, and maintenance schedules adapted to your practice.
On Microsoft 365
- SharePoint and OneDrive scoped to project teams
- Consultant and trade access reviewed at closeout
- MFA, Conditional Access, and administrator controls
- Managed endpoint protection on supported devices
On Google Workspace
- Shared drives scoped to project teams
- External links and guest access reviewed at closeout
- Gmail phishing and impersonation protection
- Google Vault aligned with retention policy where licensed
Configuration updates are part of the service. When our security baseline changes, your environment is updated without a separate project fee.
Frequently asked questions.
How do you protect project files and design information?
We secure accounts, email, file sharing, and supported devices used for project work. Microsoft 365 or Google Workspace data can also be backed up independently. CAD, BIM, rendering files, NAS devices, workstations, servers, and specialist project systems need to be identified separately so the practice knows which protection and recovery controls apply.
Can you work alongside our current provider or take over?
Yes. Managed Security & Compliance can work alongside your provider. For a handover, we document the current environment, confirm responsibilities, and schedule the transition around project deadlines. If you want to delegate day-to-day IT as well, Managed IT includes Managed Security & Compliance and adds user support, device administration, onboarding, and platform management.
What happens if a security alert is raised outside business hours?
The security team reviews alerts and follows the agreed response and escalation process around the clock. Before monitoring begins, we document which systems we cover, what access we have, and which response actions you authorize.
Can you help with a cyber insurance application or renewal?
Yes. We review the insurer’s questions and provide current evidence for the security controls we manage. Requirements vary by insurer and policy, so the work supports the application but does not guarantee approval or coverage.
Do you support both Windows and Mac devices?
Yes, for supported operating-system versions and compatible security tooling. We confirm which devices we can manage before the service begins because specialist workstations, older hardware, and application dependencies can affect what can be enrolled and how updates are scheduled.
Client feedback
What a client says about working with us.
“Teclara materially improved both our operational responsiveness and our security posture.”
E.C.
Senior Leadership, GTA Consulting Firm

Led by Wadhah Hussain, Teclara's founder
20+ years enterprise IT · Big Four alumnus · Microsoft & Google Cloud specialist
Short on time? Let your favourite AI sum up Teclara.
Review access to your project files
In a 30-minute conversation, we discuss project sharing, specialist workstations, and recovery requirements. We agree on the next step. Technical checks and written findings belong to a separately scoped engagement.
