ifctoolkit Practical tools, better compliance.

PRACTICAL TOOLS, BETTER COMPLIANCE.

Compliance and Information Security

IFC Toolkit is being developed with information security, structured data management, and construction information standards in mind.

Important compliance note

IFC Toolkit supports compliance workflows but does not automatically make a project compliant. Project teams remain responsible for their own contractual, client, security and information management requirements.

Information security approach

The platform is being developed around controlled, transparent information handling for project model data.

Session-based processing

Use session-based file processing where possible and avoid unnecessary long-term storage of uploaded model files.

Limited retention

The platform should avoid persistent storage of uploaded IFC files unless explicitly required by a user workflow.

Clear separation

Public site content is kept separate from private user and project areas.

Controlled storage

Where data is stored, it should be handled through controlled application storage and database services.

Only what is needed

Retain data only where needed for the user workflow.

Future-ready controls

The roadmap supports auditability, access control and secure project workspaces.

Standards alignment

ISO 19650

Supports structured information management principles and helps teams review naming, classification, model organisation and delivery outputs.

COBie and asset information

Supports review and extraction of data relevant to asset handover and helps identify missing, inconsistent or poorly structured information before formal submission.

IFC and openBIM

Built around IFC as an open data format, helping make model data more accessible, inspectable and usable.

Cyber and hosting considerations

IFC Toolkit is being designed to align with recognised information security principles, including controlled access, limited retention, secure hosting and clear data handling practices. Formal certifications, where applicable, should be stated separately once achieved.

Data handling principles

  • Only upload what is needed.
  • Avoid storing files longer than necessary.
  • Keep project-sensitive information controlled.
  • Use anonymised or reduced test files where possible.
  • Follow client and project-specific security requirements.
  • Do not upload security-sensitive information unless the platform and project controls are approved for that use.

Security-sensitive projects

Some projects, such as government, custodial, defence, healthcare or critical infrastructure schemes, may require enhanced controls. IFC Toolkit should not be assumed suitable for all security classifications by default.

For security-sensitive projects, teams should confirm whether IFC Toolkit is approved for use under the relevant project Security Aspects Letter, client protocol, data handling policy and contractual requirements before uploading project information.

Need to understand how IFC Toolkit handles information?