> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fieldpal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Security

> How FieldPal protects your organisation's data, for IT and security teams evaluating or deploying FieldPal.

This guide explains how FieldPal protects your organisation's data. It's written for IT and security teams who need an overview before approving FieldPal for deployment, or as a reference during a vendor security review.

<Note>
  This is a general overview. For specific compliance certifications, data residency commitments, or a completed security questionnaire, contact your FieldPal account contact directly.
</Note>

## Security at a glance

* **Encrypted in transit** — all traffic uses HTTPS with TLS 1.2 or higher. No unencrypted connections are accepted.
* **Encrypted at rest** — data is stored using AES-256 encryption, Azure's standard for data at rest.
* **Hosted on Microsoft Azure** — FieldPal runs on Azure's enterprise-grade cloud infrastructure rather than self-managed servers.
* **Individual sign-in only** — every user signs in with their own account. There are no shared logins to the dashboard.
* **Per-organisation data separation** — your organisation's data is logically isolated from every other organisation on FieldPal.

The sections below go into more detail on each of these.

## Infrastructure

FieldPal runs on Microsoft Azure. Services scale automatically to meet demand, which is why network access is controlled by DNS hostname rather than fixed IP address (see [Firewall Requirements](/security/firewall-requirements)).

## Data in transit

All communication between the FieldPal app, the dashboard, and FieldPal's backend services is encrypted using HTTPS with **TLS 1.2 or higher**. No traffic is sent unencrypted, on-site or over the internet.

## Data at rest

Uploaded documents, report data, photos, and knowledge library content are stored encrypted at rest using **AES-256**, within Azure's storage services.

## Authentication

* Sign-in is handled through Auth0, an industry-standard identity provider, rather than a custom-built login system.
* Users can sign in with email and password, or with their organisation's existing Google or Microsoft account (SSO).
* Password sign-in is protected against credential-stuffing attacks: FieldPal blocks passwords known to have been exposed in prior data breaches.
* Shared devices (tablets and headsets used by multiple field workers) authenticate individual users by card scan rather than a shared login. See [Shared devices and card users](/dashboard/shared-devices).

## Access control

* Dashboard admins control who is invited to an organisation's FieldPal workspace and what they can access. See [Inviting a mobile user](/dashboard/inviting-users).
* Field workers only see the report templates, knowledge library content, and connections their organisation has made available to them.
* Roles (user, admin, owner) control what a member can see and change on the dashboard.

## Data separation

Each organisation's data (reports, documents, connections, and knowledge library) is logically separated from every other organisation using FieldPal. One customer cannot access another customer's data.

## Offline data

The FieldPal app supports offline recordings for field workers without reliable connectivity. Data captured offline is held on the device until the app can sync it back to FieldPal's backend, at which point the local copy is no longer required. Talk to your FieldPal contact if your organisation has specific requirements around on-device data retention.

## Third-party integrations

FieldPal is API-first and can integrate with a customer's existing systems (document stores, CMM systems, ERPs) and with external data sources via [Connections](/dashboard/connections). Data shared with a third-party system is limited to what the integration or connection is explicitly configured to send or retrieve.

## Reporting a security concern

If you believe you've found a security issue affecting FieldPal, contact your FieldPal account contact or [fieldpal.ai/contact](https://fieldpal.ai/contact) directly rather than raising it through a public channel.
