Skip to content

Engineering and architecture

Which project types should an AEC firm keep out of a data license?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

An AEC firm should keep defense and export-controlled work, federal projects, critical infrastructure, detention and security facilities, data centers, private residences and projects in litigation out of a data license by default. Their restrictions come from security rules, government terms or privacy, which de-identification usually cannot cure. Flag them on the project record so every export excludes them.

Key takeaways

  • Default exclusions are set by project type, before anyone reads individual contracts.
  • De-identification does not fix security sensitivity: a floor plan with no name can still reveal a facility.
  • Tag excluded project types in Deltek, BQE or the project list so every export filters them the same way.
  • A default exclusion is reopened only by counsel and leadership, never by an individual project manager.

Why some project types are excluded by default#

Some project types are excluded from a data license by default because their restrictions come from security rules, government contracts or privacy, not from a single negotiable clause. Reviewing each of those projects one by one costs more than the records could justify, and a mistake is expensive.

A default exclusion is a starting position, not a verdict on the work. It keeps the rights review focused on projects that can realistically be cleared, and it gives the firm a clear answer when a principal asks why a favorite project is not in the package.

Default exclusions also speed up everything after them. A rights reviewer who knows that utility, federal and residential work is already out can concentrate on the commercial and institutional projects where contract wording actually decides the outcome.

The default exclusion list#

The default exclusion list below gives one reason for each project type. It applies to every record from those projects: RFIs, submittals, markups, QA/QC comments, meeting minutes and project financials.

The default exclusion list
Project typeReason to exclude
Defense and export-controlled workTechnical data may be controlled under the ITAR or the EAR, and release may be restricted by law and contract
Federal agency projectsAgency contracts often carry information-handling clauses, and some project information may be controlled unclassified information
Critical infrastructureElectric and energy records may include critical energy/electric infrastructure information (CEII), and water, utility and transportation owners often restrict security-related records
Detention, courts and security facilitiesLayouts, access control and security systems stay sensitive even without names
Data centersOwners often impose strict NDAs, and power, cooling and security designs reveal capacity and weak points
Airport and transit security areasSome records may be designated sensitive security information
Private residencesHomeowner names, addresses, floor plans and security details are personal information
Projects in litigation or under a holdRecords may be subject to preservation duties, privilege or a protective order

Projects to review closely before including#

A second tier of projects is not excluded by default but needs a closer look than ordinary commercial work. Treat each as ask-first: include only after the rights review confirms both the contract terms and the sensitivity of the content.

Second-tier projects often end up partly included. A firm might license internal QA/QC comments from a hospital project while leaving out RFIs that describe secure areas or controlled-substance rooms.

  • State and municipal projects, where public records rules and owner terms vary from one jurisdiction to the next.
  • Healthcare facilities, which rarely involve patient data in design records but may reveal pharmacy, behavioral health or security layouts.
  • Laboratories and research facilities with confidential processes or biosafety features.
  • Bank branches and financial operations centers, where vault, cash handling and security design is sensitive.
  • Schools and houses of worship whose security planning appears in the design record.
  • Corporate headquarters and campuses covered by strict NDAs or with prominent tenants.
  • Any project for a client that has sent the firm an AI or data use policy.

What de-identification cannot fix#

De-identification cannot fix a project whose sensitivity lies in the design itself. Removing the owner's name from a detention facility RFI does not hide a description of a sally port, and stripping the address from a data center submittal does not hide its cooling layout.

Distinctive buildings also defeat de-identification. A firm known for a few hospitals or stadiums in a region may find that unusual details identify the project to anyone in the local industry. When records can only be made safe by removing what makes them useful, exclusion is the better choice.

A simple test helps: hand a de-identified sample to a senior colleague who did not work on the project and ask whether they can name it. If they can, a competitor or a curious reader probably can too.

How to apply exclusions in your systems#

Exclusions work only if they are applied in the systems that feed an export. Most A/E firms already record market sector, client type or delivery method on the project record in Deltek or BQE, so build the exclusion on those fields or add a dedicated flag.

Older projects are the usual weak point. Firms that added market sector fields only recently need someone to back-fill them for closed projects, starting with the sectors on the exclusion list, before the filter can be trusted.

  • Add an exclusion field to the project record with a reason code: security, federal, infrastructure, residential, litigation or NDA.
  • Carry the project number into Procore, Bluebeam and file storage so excluded records can be filtered there too.
  • Filter on the flag at export, then spot-check the output for project names and addresses that slipped through.
  • Re-run the filter whenever projects are added, because a new hold or NDA changes the list.
  • Keep the excluded project list, with reasons, in the rights record.

Illustrative: an engineering firm draws its exclusion lines#

Illustrative: a fictional civil and MEP engineering firm with private commercial, municipal water, data center and custom residential work prepares for a licensing fit check. The CEO asks for an exclusion list before any rights review starts, so the review team does not spend time on projects that will never qualify.

The firm excludes data centers, water and wastewater utilities, a courthouse renovation and all custom residential work, and flags two projects in active disputes. It tags each in Deltek with a reason code and adds the same flag as a custom field in Procore. The remaining private commercial and institutional projects move to the rights review, and the fit check proceeds on a smaller, defensible scope.

Two months later a new data center client signs with the firm. Because the project setup form in Deltek now requires an exclusion reason code, the project is flagged on day one instead of being discovered during the next review.

How SourceX handles excluded work#

SourceX treats defense and export-controlled work as out of scope, and projects a firm flags as restricted stay out of any package. Within the SourceX five-step transaction, exclusions are set during Supply and confirmed during Rights, so excluded projects never reach Preparation.

The SourceX Evidence Packet records the exclusion rules alongside the licensing rights and the release authorization the firm signs, so a buyer, an auditor or a future acquirer can see what was left out and why.

Frequently asked questions

Can a federal project ever be licensed?

Rarely, and only after counsel reviews the specific contract, its information-handling clauses and any agency approvals. Many firms conclude the effort outweighs the records' contribution and exclude federal work outright. If one is reconsidered, the decision belongs to counsel and the principal in charge and should be documented in the rights record.

Does excluding a project exclude the lessons learned on it?

Excluding a project removes its records from the license. It does not stop the firm's staff from applying what they learned on later projects or from writing general guidance in their own words. The exclusion concerns documents and data, not the expertise of the people who did the work.

What if a custom home client is also a business client?

Treat custom residential work as personal by default, whoever the client is. Homes reveal where people live and how their houses are secured. A large multifamily rental project for a developer is different and usually goes through the normal rights review instead.

Should the same exclusions apply to internal AI tools?

Often, yes. Internal tools do not move records outside the firm, but they can show sensitive projects to staff who never worked on them. Many firms reuse the exclusion flags as access restrictions, so security-sensitive project records stay visible only to the original team.

Who maintains the exclusion list over time?

Usually the risk manager or general counsel, with project managers required to flag new holds, NDAs or sensitive owners when they arise. Review the list whenever a new package is planned, because the firm's project mix and client terms change. Note the date and approver for every change.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify