This is a general overview. For specific compliance certifications, data residency commitments, or a completed security questionnaire, contact your FieldPal account contact directly.
Security at a glance
- Encrypted in transit — all traffic uses HTTPS with TLS 1.2 or higher. No unencrypted connections are accepted.
- Encrypted at rest — data is stored using AES-256 encryption, Azure’s standard for data at rest.
- Hosted on Microsoft Azure — FieldPal runs on Azure’s enterprise-grade cloud infrastructure rather than self-managed servers.
- Individual sign-in only — every user signs in with their own account. There are no shared logins to the dashboard.
- Per-organisation data separation — your organisation’s data is logically isolated from every other organisation on FieldPal.
Infrastructure
FieldPal runs on Microsoft Azure. Services scale automatically to meet demand, which is why network access is controlled by DNS hostname rather than fixed IP address (see Firewall Requirements).Data in transit
All communication between the FieldPal app, the dashboard, and FieldPal’s backend services is encrypted using HTTPS with TLS 1.2 or higher. No traffic is sent unencrypted, on-site or over the internet.Data at rest
Uploaded documents, report data, photos, and knowledge library content are stored encrypted at rest using AES-256, within Azure’s storage services.Authentication
- Sign-in is handled through Auth0, an industry-standard identity provider, rather than a custom-built login system.
- Users can sign in with email and password, or with their organisation’s existing Google or Microsoft account (SSO).
- Password sign-in is protected against credential-stuffing attacks: FieldPal blocks passwords known to have been exposed in prior data breaches.
- Shared devices (tablets and headsets used by multiple field workers) authenticate individual users by card scan rather than a shared login. See Shared devices and card users.
Access control
- Dashboard admins control who is invited to an organisation’s FieldPal workspace and what they can access. See Inviting a mobile user.
- Field workers only see the report templates, knowledge library content, and connections their organisation has made available to them.
- Roles (user, admin, owner) control what a member can see and change on the dashboard.