Trust Security and Compliance

Security

Security & Compliance

Documentation, certifications, insurance coverage, and contractual frameworks that satisfy enterprise procurement requirements.

Page last reviewed: May 2026

Talk to our Compliance Lead
Reviewed quarterly ISO 9001 · 14001 · 45001 · 27001 · 19650 E&O $2M · A+ AM Best
At a Glance
Founded
2009 · 16+ years
ISO Certifications
9001 · 14001 · 45001 · 27001 · 19650
E&O Insurance
$2M · Everest Insurance
Headquarters
Hollywood, Florida
General Liability
$2M aggregate
Cyber Insurance
Coverage in place
Delivery Centre
Dubai, UAE
NDA Available
Standard mutual
COI Available
On request · same day
Certifications

ISO Certifications

Gsource maintains five active ISO certifications covering quality management, environmental responsibility, information security, occupational health and safety, and BIM information management. Each certification is independently audited annually.

ISO 9001:2015Quality Management Systems

Gsource maintains a certified quality management system designed to support the full project lifecycle, from intake to final delivery. The framework establishes QA checkpoints at drafter, senior reviewer, and discipline-lead levels; documents non-conformance handling procedures; and supports continuous process improvement. Internal audits are conducted quarterly, with annual external surveillance audits.

Last audit: [03 November 2025]
ISO 14001:2015Environmental Management Systems

Gsource follows a certified environmental management framework focused on office operations, energy consumption, waste management, and environmentally responsible procurement practices. The system defines processes for monitoring environmental impact and driving continuous operational improvement. Internal reviews are conducted quarterly, with annual external audits.

Last audit: [03 November 2025]
ISO 27001:2022Information Security Management

Gsource adheres to a certified information security management framework focused on data classification, access control, encryption protocols, secure file exchange, incident response, and outsourcing partner security practices. The system is designed to safeguard client and project information across all stages of delivery. Internal audits are conducted quarterly, supported by annual penetration testing and external surveillance audits.

Last audit: [06 November 2025]
ISO 45001:2018Occupational Health & Safety

Gsource follows a certified occupational health and safety management framework focused on workstation ergonomics, employee wellbeing, incident reporting, emergency preparedness, and workplace safety practices across all delivery centres. The system supports a safe and structured working environment through regular monitoring and continuous improvement initiatives. Internal reviews are conducted quarterly, with annual external audits.

Last audit: [03 November 2025]
ISO 19650-1:2018Information Management for BIM

Gsource applies a certified BIM information management framework governing how project information is structured, named, exchanged, reviewed, and archived across BIM workflows. Aligned with the BS EN ISO 19650 series, the framework supports consistent collaboration across multidisciplinary and federated model environments. Internal process reviews are conducted regularly, with annual external compliance audits.

Last audit: [04 November 2025]
Insurance

Insurance & Risk Coverage

Gsource maintains professional liability and general business insurance coverage that meets or exceeds standard requirements for enterprise AEC Partner onboarding. A current Certificate of Insurance (COI) is available on request, and additional insured / waiver of subrogation / primary & non-contributory endorsements can be issued for client-specific MSAs.

Coverage TypeCarrierLimitEffective Period
Professional Liability (Errors & Omissions)Everest Insurance$2M per claim · $2M aggregate[Policy term]
Commercial General Liability[Carrier]$2M aggregate · $1M per occurrence[Policy term]
Workers' Compensation[Carrier]Statutory[Policy term]
Cyber Liability[Carrier][Limit][Policy term]
Umbrella / Excess Liability[Carrier][Limit, if applicable][Policy term]
Waiver of SubrogationAvailable on request - issued per client MSA
AM Best Rating: Everest Insurance carries an A+ (Superior) rating from AM Best, the standard rating agency for insurance carrier financial strength.
Data Security

How We Handle Your Project Data

Project data is handled under the ISO 27001:2022 framework with documented policies for classification, access, transmission, storage, and destruction. The protocols below apply to every project regardless of engagement model.

01

Data Classification & Access Control

Project files are classified per client and access-controlled to NDA-bound team members assigned to that engagement only. Access is provisioned at engagement kickoff and revoked at engagement close. Cross-project data sharing is technically and contractually prohibited.

02

Encrypted File Exchange

Project files are exchanged through Gsource’s proprietary secure data management platform, designed to support controlled access, encrypted transfers, and protected collaboration across global project teams. All file transfers use TLS 1.2 or higher, while unsecured email-based file sharing is restricted and discouraged.

03

Storage & Backups

Project data is stored on access-controlled servers within delivery centres, with encrypted backups on a defined retention schedule. Backups are tested quarterly. No project data is stored on personal devices or unmanaged endpoints.

04

Network & Endpoint Security

All workstations are managed endpoints with enforced full-disk encryption, anti-malware, and centralised patch management. Network segmentation isolates client project environments. USB ports and external storage are policy-restricted on production workstations.

05

Incident Response

A documented incident response plan defines detection, containment, notification, and post-incident review procedures. Clients are notified of any incident affecting their data within the timeframe specified in the engagement agreement (typically 48 hours).

06

Data Destruction at Engagement End

At engagement close, project data is either returned to the client or securely destroyed per the terms of the engagement. Destruction certificates are issued on request.

Contracts

Contractual & Commercial Framework

Gsource works under standard mutual non-disclosure agreements and engagement-specific master service agreements. Standard templates are available for review prior to engagement; clients may also request execution under their own MSA forms.

Non-Disclosure Agreement (NDA)

A standard mutual NDA template is available for download. Key terms: bilateral confidentiality, 5-year term post-engagement, indemnification for unauthorised disclosure, and explicit prohibition on cross-engagement data use. Custom NDA forms are accepted with reasonable revision timelines.

Master Service Agreement (MSA)

Engagement-specific MSAs cover scope, deliverables, pricing, intellectual property, indemnification, limitation of liability, and termination terms. Client-form MSAs are accepted - approximately 70% of enterprise engagements run on the client's paper.

IP & Work-Product Ownership

All deliverables - drawings, models, calculations, reports, source files - are the client's property at the moment of delivery. Gsource retains no rights to client work product. Gsource retains rights only to internal tools and methodologies developed independently of client engagement.

Codified in every MSA · client form or Gsource form
Compliance

Compliance & Regulatory Adherence

Gsource adheres to relevant industry standards and applicable data privacy regulations across jurisdictions where clients operate.

Industry Standards

  • IBC - International Building Code
  • NEC - National Electrical Code
  • IECC - International Energy Conservation Code
  • NFPA - National Fire Protection Association
  • ASHRAE
  • SMACNA
  • IEEE
  • AISC, ACI, NDS, ASTM (structural)
  • US National CAD Standard (NCS)
  • AIA Standards
  • BS EN ISO 19650 series

Data Privacy & Regional

  • GDPR-aligned handling for EU client data
  • CCPA-aligned handling for California client data
  • Region-specific data residency available on request
  • Sub-processor list maintained and disclosed in MSA
Onboarding

Partner Onboarding Pack

Most enterprise procurement teams require a standard set of documents to onboard Gsource as an approved outsourcing partner. The pack below consolidates everything typically requested. Some documents are immediately downloadable; others require a brief request form to ensure the document version is current and signed.

Includes - 10 items
Current Certificate of Insurance (COI) with carrier names and policy numbers
All five ISO certificates (PDF copies)
Standard mutual NDA template
Standard MSA template
Information Security Whitepaper
W-9 / W-8BEN-E (US tax forms, as applicable)
Banking & remittance details (post-MSA)
Sub-processor list
Most recent ISO 27001 audit summary letter
Sample security questionnaire responses (SIG Lite, CAIQ-Lite)

Get the full pack

Single request form. Pack delivered within 1 business day, signed and current.

Procurement FAQ

Common Procurement Questions

Trimmed for Partner-questionnaire workflows. For questions not covered here, contact the compliance team directly.

Does Gsource carry sufficient E&O coverage for enterprise engagements?
Gsource carries $2M per-claim and $2M aggregate Professional Liability coverage with Everest Insurance, which holds an A+ Superior rating from AM Best. For very large engagements, project-specific endorsements or supplemental coverage are available - typically negotiated as part of the MSA.
Can Gsource execute under our MSA template instead of yours?
Yes. Approximately 70% of Gsource's enterprise engagements are executed under client-form MSAs. Reasonable redline turnaround is typically 5–10 business days.
Where is project data stored, and can we require regional data residency?
Project data is stored at Gsource's delivery centres in Dubai (primary) and Pune (secondary), with encrypted backups. Regional data residency requirements (e.g., US-only storage) are available - typically configured at engagement kickoff and included in the MSA.
Who owns the work product?
The client owns all deliverables - drawings, models, calculations, source files - at the moment of delivery, unless explicitly modified in the MSA. Gsource retains no rights to client work product.
What is your incident notification timeframe?
Within 48 hours of confirmed incident detection, unless a different timeframe is specified in the MSA. Initial notification is followed by a written incident report within 5 business days.
Do you carry Cyber Liability insurance?
Yes. Coverage details available in the COI. Specifically covers data breach response, regulatory defence, and notification costs.
Are subcontractors used? How are they vetted?
Gsource does not subcontract production work to third parties. All work is performed by employees at Gsource delivery centres. The current sub-processor list (covering only software and infrastructure providers) is included in the Partner Onboarding Pack.
What happens to our project data when the engagement ends?
At engagement close, data is either returned to the client per MSA terms or securely destroyed. Destruction certificates are issued on request. Standard practice: 30-day retention post-engagement-close, then secure deletion.

Need something specific?

For procurement-specific questions, security questionnaire responses, or supplemental documentation requests, contact the Gsource compliance team directly.

Typical response time: 1–2 business days
Email Compliance

(Enter captcha image text in box)

USA (Corporate Address)

UAE

Pune

Mumbai