Platform Overview
How LuxGov Works
Compliance Intelligence. Human Authority.
LuxGov is a purpose-built compliance governance platform for the construction industry. It replaces ad-hoc compliance workflows with a structured, deterministic governance engine — one where every rule is traceable, every document is stored with legal-grade integrity, and every verdict is confirmed by an authorised human being. Not a document manager. Not a checklist. A governance system.
The Core
A governance engine — not a workflow tool
At the centre of LuxGov is a deterministic rules engine. Unlike AI-generated outputs that vary with context, the governance engine applies fixed, coded regulatory logic against your documents and produces the same result every time for the same input. There is no ambiguity. There is no inference. There is a rule, and there is a verdict.
The AI advisory layer sits alongside the engine — not inside it. AI surfaces relevant clauses, flags risk signals, and structures regulatory information for human review. Removing AI from the system entirely does not change a single compliance outcome. The engine runs the same with or without it.
Important: LuxGov does not make compliance decisions. The platform computes verdicts based on coded regulatory rules and presents them for confirmation by an authorised human role. No automated action is taken without human sign-off. This is a design principle, not a setting.
Process Flow
From document to governed verdict
Every compliance check follows the same structured sequence — from ingestion to human-confirmed outcome.
01
Evidence Ingestion
Documents are submitted through the platform — PDF, DOCX, or XLSX files — or imported directly from SharePoint (Professional and Enterprise plans). Each file is classified, validated for size and format, and assigned to the correct jurisdiction and tenant. No file is stored without a validated tenant identity.
02
Jurisdiction Routing & Regulatory Matching
The platform identifies the applicable jurisdiction — Malaysia, Australia, Singapore, United Kingdom, or United States — and loads the corresponding regulatory ruleset. For drawing checks, this means clause-level rules: UBBL 1984 for Malaysia, NCC 2022 for Australia. Each document is matched against the rules that legally apply to it, not generic compliance logic.
03
AI Advisory Analysis
The AI advisory layer reads the document and surfaces risk signals — potential clause violations, missing elements, or dimensional discrepancies flagged against the applicable regulatory standard. This output is advisory only. It is structured for human review, not presented as a determination. The governance engine then runs its own deterministic check independently.
04
Governance Engine Verdict
The rules engine applies the jurisdiction's coded regulatory logic and produces a deterministic verdict — compliant, non-compliant, or requires review — with specific clause references and evidence citations. This is not a probability score. It is a structured regulatory determination based on traceable rules.
05
Human Authority Confirmation
Every verdict requires confirmation by an authorised human role before any action is taken. Depending on the organisation's role configuration, this may be a Reviewer, Auditor, Certifier, or Lead Auditor. The role hierarchy is enforced at the platform level — no lower-level role can confirm a verdict that requires a higher authority.
06
Audit Log & Sovereign Storage
Every action — document submission, AI advisory output, engine verdict, human confirmation — is written to an immutable audit log and stored in sovereign infrastructure. Data is physically stored in the correct country for the jurisdiction in question. Audit logs are WORM-protected and cannot be overwritten or deleted through any platform code path.
Platform Capabilities
What the platform actually does
Every capability listed here is live in the platform — not planned, not aspirational.
📐
Drawing Verification Engine
Structural and architectural drawing analysis at clause level. The engine checks dimensions, clearances, and structural elements against the applicable regulatory standard — UBBL 1984 clause by clause for Malaysia, NCC 2022 for Australia. Discrepancies are flagged with the specific clause reference and the measured versus required value.
All Plans
📋
Evidence Pipeline
Structured ingestion and classification of compliance evidence. Supports PDF, DOCX, and XLSX uploads. Professional and Enterprise plans add direct SharePoint import — documents flow from your organisation's SharePoint library into the governance pipeline without manual re-upload.
Standard · Pro · Enterprise
🔐
Role-Based Authority Controls
Nine distinct roles enforced at the platform level — from read-only through to system administrator. Every role has defined permissions for what it can view, action, and confirm. No role can exceed its authority. Human confirmation of verdicts is mandatory and role-gated.
All Plans
🗄️
Sovereign Storage Infrastructure
Data is physically stored in-country for the jurisdiction it belongs to. Malaysia data stays in Malaysia West. Australia data stays in Australia East. United Kingdom data stays in UK South. This is not a routing preference — it is enforced at the storage account level, with separate accounts per jurisdiction, each with its own WORM policy.
Enterprise
🧾
Immutable Audit Logs
Every platform event is written to a WORM-protected audit trail. Standard plans retain 90 days. Professional plans retain 1 year. Enterprise plans retain 7 years for Australian and US jurisdictions — meeting QBCC Act and State Construction Law retention requirements — with HARD WORM protection that prevents deletion through any code path.
All Plans · Extended on Pro & Enterprise
🏢
Multi-Tenant Isolation
Each organisation operates in a fully isolated tenant environment. Row-level security enforces data separation at the database layer — no tenant can access another tenant's data, documents, verdicts, or audit logs. Tenant identity is validated from a cryptographically signed token, never from a request parameter.
Enterprise
Jurisdictions
Five regulatory environments. One platform.
LuxGov operates under five jurisdictions, each with its own regulatory ruleset, sovereign storage account, and WORM policy. The platform applies the correct rules automatically based on the jurisdiction assigned to the document.
🇲🇾
MY
Malaysia
UBBL 1984
CIDB Act
BOMBA
PDPA 2010
Soft WORM
🇦🇺
AU
Australia
NCC 2022
QBCC Act 1991
Hard WORM 7yr
🇸🇬
SG
Singapore
PDPA 2012
Soft WORM
🇬🇧
UK
United Kingdom
UK-GDPR Art.17
Soft WORM
🇺🇸
US
United States
State Construction Law
Hard WORM 7yr
WORM explained: Soft WORM means audit logs cannot be overwritten by platform code, and supports Right to Erasure for GDPR and PDPA compliance via a controlled purge process. Hard WORM (Australia and United States) means documents are placed under a time-based immutable hold — no deletion is possible through any code path for the full retention period. This meets the regulatory requirement for long-form construction audit retention in those jurisdictions.
Authority Structure
Nine roles. Clear authority at every level.
Every user in LuxGov operates within one of nine defined roles. Roles are assigned by a Tenant Administrator and enforced by the platform — a user cannot perform an action their role does not permit, regardless of how the request is made.
0
Read Only
View compliance records and audit logs. No action permissions.
Standard
1
Reviewer
Review submitted documents and AI advisory outputs. Cannot confirm verdicts.
Standard
2
Intake Operator
Submit documents to the evidence pipeline and assign jurisdiction.
Professional
3
Auditor
Conduct compliance audits and confirm lower-level verdicts.
Professional
4
Certifier
Issue compliance certifications. Requires qualified professional status.
Professional
5
Lead Auditor
Oversee audit programmes and confirm final verdicts across a project.
Professional
6
Tenant Billing
Manage subscription, payment methods, and billing records.
Professional
7
Tenant Admin
Manage all users, roles, departments, and tenant configuration.
Enterprise
8
System Admin
Full platform access including ops monitoring and cross-tenant visibility.
Enterprise
Subscription Plans
Three plans. Clear boundaries. No hidden limits.
Every plan runs on the same governance engine and the same infrastructure. The difference is in jurisdictional reach, role depth, retention period, and data sovereignty. Choose the plan that matches where your organisation operates and what your regulatory obligations require.
Standard
RM 299
per project / month
- Core Engine
- Deterministic governance rules engine
- Drawing verification — UBBL 1984 & NCC 2022
- Evidence ingestion — PDF, DOCX, XLSX
- Jurisdiction
- Single jurisdiction (MY, AU, SG, UK, or US)
- Applicable regulatory rules loaded automatically
- Access & Roles
- Roles 0–1: Read Only and Reviewer
- Microsoft Entra identity login
- Storage & Audit
- Audit log retention — 90 days
- Soft WORM audit trail
- Compliance dashboard & PDF/DOCX exports
- Billing
- Stripe — MYR & FPX supported
Get Started
Most Popular
Professional
RM 599
per project / month
- Everything in Standard, plus
- AI advisory layer — surfaces risk signals & relevant clauses
- SharePoint document import pipeline
- Jurisdiction
- Up to 3 jurisdictions (any combination)
- Multi-jurisdiction routing — automatic
- Access & Roles
- Roles 0–6: up to Lead Auditor & Billing Admin
- Priority human review queue
- Certifier & Lead Auditor authority controls
- Storage & Audit
- Audit log retention — 1 year
- Extended Soft WORM trail
- Structured audit exports for regulatory review
Get Started
Enterprise
RM 1,499
per project / month
- Everything in Professional, plus
- All 5 jurisdictions — MY, AU, SG, UK, US
- Physical sovereign storage per country
- Hard WORM 7-year retention (AU & US)
- Access & Roles
- All 9 roles — incl. Tenant Admin & System Admin
- Complete row-level tenant isolation
- Configuration
- Custom department & jurisdiction configuration
- Ops monitoring dashboard
- Unlimited projects under one tenant
- Onboarding
- Dedicated onboarding & same-day setup
Get Started
All plans include a 10-day free trial. Billing is processed via Stripe — Malaysian Ringgit and FPX bank transfer are supported. Yearly billing is available at approximately 17% discount. Contact admin@luxgov.net for enterprise procurement arrangements.
Data Integrity
Audit logs that cannot be altered. By design.
Every compliance action in LuxGov is written to a WORM-protected audit trail. WORM stands for Write Once, Read Many — once a record is written, it cannot be modified or deleted through any code path in the platform. The type of WORM protection varies by jurisdiction based on regulatory requirement.
Soft WORM
Malaysia · Singapore · United Kingdom
Audit records are write-protected and cannot be overwritten by platform operations. Supports Right to Erasure — a controlled purge process exists for GDPR and PDPA compliance, allowing deletion of personal data upon valid legal request. This satisfies the data subject rights requirements under UK-GDPR Article 17 and Malaysia's PDPA 2010.
Hard WORM — 7 Year Hold
Australia · United States
Audit records are placed under a time-based immutable hold at the infrastructure level. No deletion is possible through any code path — including platform administrators — for the full 7-year retention period. This satisfies the long-form construction audit retention requirements under the QBCC Act 1991 (Queensland) and applicable US State Construction Law.
Why LuxGov
The difference is authority — not workflow.
Other platforms manage your project or manage your documents. LuxGov governs your compliance. That distinction matters when a building permit is delayed, when a contractor's licence is questioned, or when a regulator asks for a full audit trail of how a compliance decision was reached and by whom.
LuxGov exists because compliance in construction has been treated as paperwork for too long. Approvals get delayed because authority is unclear. Risks stay hidden because nobody owns the outcome. And when something goes wrong, there is no audit trail that shows who decided what, based on which rule, on which date.
LuxGov changes that. Every decision is owned by a named, authorised human. Every verdict is traceable to a regulatory clause. Every document is stored with legal-grade integrity. That is governance — not workflow management.
LuxGov is built and operated by Luxemss Resources, registered under SSM Malaysia. For enquiries, custom SaaS builds, or enterprise procurement, contact admin@luxgov.net or visit www.luxgov.net.