HESYS

INFORMATION / DATA & SECURITY

Your engineering.
Your information.

Understand where project information goes, what account access means, and how we are developing HESYS security.

01 / PROJECT INFORMATION

Local files and cloud storage.

A website can run engineering calculations in your browser while also offering cloud features. Where a project is saved is a separate choice from where a calculation runs.

Portable project files

The Settlement trial supports saving and opening a portable .hesys project file. Keep a copy in a location controlled by you or your organisation, and retain the source drawings separately. A project file is not a complete archive of every source document.

You manage access and backups for these copies. A folder synced to OneDrive or another service may itself be cloud storage.

Portal project storage

Saving a project to your portal account sends project information to HESYS cloud storage on Microsoft Azure. Account-based saves and local downloads are different actions.

Portal access and saved projects are associated with your account. See the portal privacy information for the data handled by the portal and how to request assistance.

A dedicated local-only mode

Proposed, not currently a product promise. We are considering a mode for design tools in which project calculations and files remain on your device, with project uploads and connected features disabled.

This would need separate verification before we could claim that project data never leaves your device. Sign-in and licensing may still require an internet connection.

Different products have different needs

The HESYS Inspect document pilot provides project libraries shared with explicitly assigned members. Photo capture and inspection workflows are planned. See the Inspect product page and project privacy information for the pilot scope and storage arrangements. Do not assume that one product’s storage arrangements apply to every HESYS product.

02 / IDENTITY & ACCESS

Sign in. Then check permission.

The client portal uses Microsoft work or school account sign-in. Access to a product also depends on the permissions assigned to the account.

Microsoft sign-in

Microsoft handles your sign-in credentials; HESYS does not ask you to provide your Microsoft password to our engineers. The current portal requires a work or school account, rather than a personal Microsoft account.

Product access

Verified Howl Engineering staff accounts receive staff product access. External clients require an assigned entitlement. Staff product access does not automatically give employees access to another client’s saved projects.

Protect your account

Use your organisation’s approved authentication methods, enable multi-factor authentication where available, keep your device updated and sign out on shared devices. Sign-in alone should not be interpreted as a guarantee that MFA is enforced for every account.

03 / CONNECTED FEATURES

Understand what is sent.

Engineering calculations

The Settlement trial’s ground movement calculations and 2D finite element solver run in the browser. This does not mean the whole application is offline: account access, cloud saves and other connected features make network requests.

AI-assisted document processing

Azure AI document extraction is not enabled in this website’s Settlement portal at present. If introduced, we intend to explain which information is sent, to which service, and the applicable retention arrangements before you choose to submit it.

AI outputs would require engineering review. Do not upload confidential documents to an AI service without the necessary authority.

Maps and other services

Online maps and externally hosted components can contact third-party services. Map requests can disclose your network address and the area being viewed. Local project files alone do not disable these connections.

04 / SECURITY APPROACH

Layers of protection.

HTTPS protects information in transit between your browser and the website. Microsoft Azure provides the hosting platform. HESYS remains responsible for the application, access configuration and the way we handle information.

Our improvement priorities

Strengthening authentication, limiting administrative access, verifying separation between customer accounts, protecting credentials, and checking backup recovery are priorities for our security programme.

These are improvement priorities, not a claim that every control has already been independently verified.

ISO/IEC 27001

We intend to use ISO/IEC 27001 to inform the development of our information security management system: identifying risks, assigning responsibilities, maintaining controls and reviewing their effectiveness.

HESYS is not currently ISO/IEC 27001 certified. Microsoft’s certifications apply to their defined service scope and do not certify HESYS or Howl Engineering’s application or operations.

Discuss your requirements

If your project has requirements for data location, retention, access, confidentiality or procurement assurance, contact us before using HESYS with that information.

Ask an Engineer →

To report a security concern, contact info@howlengineering.com. Please describe the concern without including passwords or confidential project files.

Provider and standards information: Microsoft shared responsibility · Microsoft Azure ISO/IEC 27001 scope · ISO/IEC 27001 overview.

CLEAR INFORMATION. INFORMED CHOICES.

Have a project
requirement?

Talk to us about how your team needs to work and the information you need to protect.

Ask an Engineer →