Menu

Data handling

How documents are handled

For security reviews: what TworkX sends when it reads a document, where it goes, how long it is kept and who can see it.

What is read, and when

TworkX can read a geotechnical report or a set of drawings, into a brief or into a project's site data, and propose the values it states, such as borehole logs, groundwater levels, the drawing register, dimensions, levels and the concrete specified, and for a brief the answers to its questions that the pages state. Each proposed value or answer shows the page and the words it was read from, and nothing goes into a brief or the site data until its author accepts it.

Document reading is off until a company's administrator switches it on, confirming the company allows its documents to be sent to the service named. If the service is changed, it is off again until confirmed for the new one. After that, a document is sent only when its author picks its pages and confirms, or, for a markup or sketch, when its author drops it on a brief under the statement that it will be read straight away. Every brief can still be completed without it.

A value whose words cannot be checked against the page's text (not found there, not holding the value, or read from a page with no text, such as a scan) is marked and can only be accepted on its own, after the author has looked at the page. An answer read from a document is proposed only for a question the brief asks, and never replaces an answer the author wrote unless the author chooses it.

What is sent

Only the pages the author picks, or every page of a markup or sketch dropped on a brief, at most 20 for one reading, with the document's file name and a fixed instruction saying which values the brief or the site data uses and, for a brief, which of its questions that kind of document may answer, in the question set's own words. The pages are copied into a new file that holds nothing of the other pages: links, shared images and anything else that refers to another page are left out. No other part of the brief or the project is sent. A PDF protected against changes is turned away before anything is sent.

A document chosen from the author's computer is opened in the author's browser. The text of its pages is read there to list them and suggest which to send, and the pages picked are copied into the new file there, so only that file leaves the author's computer and the rest of the document stays on it. When the file arrives, TworkX checks it again: it must hold exactly the pages named, no more than 20, and each page is copied again in the same way before anything goes on to the reading service. A document the author has already attached to a brief is stored with the brief, so its pages are copied out in the same way by TworkX.

Where it goes

To the reading service your company sets up. The default is Claude in Amazon Bedrock in Australia. The request is made in Sydney (ap-southeast-2) through Amazon Bedrock's Australian cross Region inference profile, which AWS documents as routing a request from Sydney only to Sydney or Melbourne (ap-southeast-4), so the pages are processed in Australia. Traffic between the two regions stays on the AWS network and is encrypted, and AWS says that where it keeps a request for abuse detection, it keeps it in the region that processed it. The application accepts only the Australian profiles, so no setting can send the pages to a global or overseas profile, and it refuses any address for the service other than Amazon Bedrock's own.

Anthropic's documentation says requests to Claude Sonnet 5 (the default), Claude Opus 5.5, Claude Opus 4.8 and Claude Opus 4.7 are served by the same infrastructure as Claude in Amazon Bedrock, which it describes as running on AWS managed infrastructure with zero operator access. Claude Haiku 4.5, also offered, runs on Bedrock's earlier integration, where AWS states that model providers have no access to the accounts the models run in, to Bedrock's logs or to customers' prompts and completions. Where a company uses its own AWS account, its security review can confirm where each request was processed: AWS CloudTrail logs each request in Sydney with the region that served it.

The alternative is Anthropic's Claude API, offered only where the company has an agreement with Anthropic for zero data retention. The Claude API may process requests outside Australia, so a company that needs its pages processed in Australia should use Amazon Bedrock. A company can also use its own AWS account or its own agreement with Anthropic.

Pages go in the reading request itself, within the size the service accepts. The services' file storage and batch features are not used, and only the models the application lists can be set.

How long it is kept

TworkX does not store a document chosen for reading. A document from the author's computer stays there, apart from the pages picked, which are read in memory for that request and discarded; a document the author has separately attached to a brief stays as that attachment.

A proposed value or answer waiting for the author is saved with the brief, or with the project's site data, with its page number and the few words it was read from. Accepting it keeps the value and a reference to the document and page, without the words; dismissing it removes it.

How the reading service handles a request is set by its terms: Amazon Bedrock's data protection terms for Claude in Amazon Bedrock, and the company's zero data retention agreement for the Claude API.

What is recorded

Each reading is logged with who asked for it, when, the project and the brief it was read into, the document's file name, the service and model, how many pages were sent, how many values were proposed and whether it finished, including a reading that failed after the pages were sent. The log never holds what the document says or a message from the service.

Who can see it

The values and answers accepted are part of the brief, or of the project's site data, and are seen by whoever can see it, as are those still waiting with their words. The reading itself goes back only to the author who asked for it. Values and answers still waiting when a brief is issued are removed with their words.

What it never does

Reading never enters a value or an answer itself: what it reads is proposed, and the author confirms it. It never evaluates a rule, never decides whether anything is adequate and never produces numbers to build from. It records what the pages state, and the author decides.

How TworkX protects data more generally, the services that handle it and how to report a security problem are on the Security page.

The application and its database are hosted in Australia. Updated 7 October 2026.