Best practices for templates, workflows, approvals, and reporting.
Data migration and go-live readiness checklists.
Certification or competency paths
Some partners offer certification or formal recognition for admins or power users.
Post-implementation support
Access to a dedicated support team or account manager.
Regular health checks, optimization sessions, and periodic refresher trainings.
Support channels
Email, web portal, and phone support depending on the service tier.
SLA-based response times, depending on cloud vs. on-prem and support tier.
Knowledge base and community
Online knowledge base with articles, FAQs, and troubleshooting guides.
Customer community or forum access (where available) for peer tips and shared solutions.
Security Measures
User access and authentication
Role-based access control (RBAC) to restrict data by user role.
Support for single sign-on (SSO) in enterprise environments.
Strong password policies and multi-factor authentication (MFA) where supported.
Data protection
Data encryption in transit (TLS) for all communications.
Data at rest encryption options (where applicable, especially for cloud deployments).
Operational security
Security policies and procedures for cloud hosting or on-prem environments.
Regular access reviews and audit trails for sensitive actions (e.g., changes to bids, change orders, approvals).
Backup and disaster recovery
Cloud deployments typically include automated backups and DR planning.
On-prem deployments rely on customer or partner-defined DR strategies; ensure backups and restore procedures are documented.
Compliance and governance
Adherence to common industry standards where relevant (privacy, data handling, and industry-specific requirements).
Data residency options may be available depending on deployment and region.
Monitoring and incident response
Security monitoring as part of managed cloud services; incident response plans in place with defined SLAs.
Updates
Update cadence
Cloud (SaaS): Regular automatic or semi-automatic updates at the platform level, with new features and security patches rolled out on a defined schedule (monthly or quarterly in many cases).
On-prem: Updates are typically released as new versions or service packs that you install, with a planned maintenance window.
What updates typically cover
Feature enhancements and new module capabilities.
Security patches, bug fixes, and performance improvements.
Updates to templates, libraries, and integration connectors as needed.
Deployment and testing
Cloud: Updates are generally transparent to users; you may be notified of upcoming changes and can sometimes opt into new features in a controlled manner.
On-prem: Upgrade planning is needed; teams test in a staging environment before production deployment.
Versioning and compatibility
Major version updates may require planning for compatibility with integrations (ERP, BIM, CRM), so verify connector compatibility during upgrade planning.
Change management
Release notes are provided outlining new features, deprecations, and any configuration changes.
Training or quick-start refreshers may accompany significant releases to help users adapt.
Data Ownership and Portability
Data ownership
You generally retain ownership of your data that you input into Corecon (project data, estimates, bids, schedules, cost histories, documents, etc.).
Corecon typically acts as a data processor/host for your data when using cloud services, and as a steward for data access and security per the contract.
Data access and export rights
You should have the ability to export your data in common formats (e.g., CSV, Excel, PDF, and structured project data) for offline use, reporting, or migration.
Data export rights are commonly included at contract termination or upon request, subject to any reasonable data-migration windows or fees.
Portability and data formats
Ensure availability of a documented data schema and an export mechanism for core entities
Bids, change orders, progress updates, and financial transactions
Documents and attachments (where supported, e.g., via downloadable archives)
Data retention after termination
Contracts typically specify a data-retention period during which you can retrieve or import your data after termination.
After the retention period, data may be securely deleted unless you negotiate an extended retention or
Scaling Up / Down
Cloud (SaaS) scaling
Flexible user-seat scaling: add or remove users with the monthly/annual subscription adjustments.
Module-level scaling: enable or disable modules as needs change (e.g., add BIM/CRM or remove a module).
Pricing adjusts pro-rata based on changed user counts and module selections.
On-prem or hosted deployments
Scaling primarily affects licenses, hardware/resource planning, and maintenance scope.
Additional licenses can be acquired for new users or modules; you’ll typically negotiate volume discounts or tiered pricing.
Decommissioning licenses may involve data migration/cleanup and potential deactivation steps.
Implementation impact
Major scale changes (e.g., moving from few to many users, or adding complex integrations) may trigger an additional implementation/upgrade activity to ensure performance and governance.
The terms & conditions for contract renewal and cancellation
Renewal structure
Typically annual (or multi-year) subscriptions for Cloud; perpetual licenses with annual maintenance for On-prem.
Pricing may be fixed for a term or subject to annual increases (price escalators).
Renewal notices: usually required weeks to months in advance; check for auto-renewal terms and how to opt out.
Cancellation rights
Cloud: cancellation usually possible at the end of a term with appropriate notice; some contracts may allow mid-term termination with penalties unless specified by “no penalty” clauses.
On-prem: cancellation often corresponds to end of license term; you may stop renewals for maintenance, but access to updates may cease unless negotiated.
Data handling at renewal/cancellation
Data export rights typically survive termination; you should be able to retrieve data post-termination within the retention window.
Any data migration assistance post-termination may be offered as a separate service.
Fees and penalties
Early termination penalties are possible in some enterprise agreements; verify if any early termination fees exist.
Surcharges for pro-rated time, data export, or incremental onboarding in renewal scenarios should be disclosed.
SLA and support during renewal
Confirm existing SLA coverage continues through renewal and whether support tiers change at renewal.
Any changes to support levels, response times, or availability should be communicated ahead of renewal.
Upgrade and migration options
Renewal may include options to upgrade to newer editions, add modules, or adopt cloud migration if currently on-prem.
Migration assistance terms (scope, duration, and cost) should be clarified.
Compliance
Common compliance frameworks relevant to Corecon deployments
Data protection and privacy standards appropriate to cloud deployments (e.g., general data privacy requirements) depending on region.
Information security management practices aligned with common industry standards as applicable to the hosting model.
Security certifications (typical expectations)
Certifications related to the cloud hosting environment (ISO 27001, SOC 2 type II, or equivalent) are often pursued by cloud providers or hosting partners.
Compliance attestations for data handling, encryption, and access controls.
Data residency and governance
Data residency options may be available for cloud deployments, enabling storage in specific geographic regions.
Governance controls, access logging, and audit trails are typically available to support regulatory inquiries.
Industry-specific considerations
For construction/project management data, there may be alignment with general data privacy laws (e.g., GDPR in Europe, CCPA in California) depending on where data is processed and stored.
If you must comply with sector-specific requirements (e.g., defense, healthcare, or highly regulated environments), verify that Corecon’s security posture and hosting arrangements meet those obligations.
Audit and reporting capabilities
Audit logs for user access, configuration changes, and critical actions (change orders, approvals, financial adjustments) are commonly available.
Security or compliance questionnaire responses can often be provided as part of vendor due diligence.