Skip to main content
Skip to content
Field2Base
Security & Compliance

Enterprise-grade security for your field data

SOC 2 Type II certified. HIPAA / HITECH aligned. Built from the ground up to protect sensitive operational data across regulated industries.

SOC 2 Type II

Certified

Annual independent audit verifying security controls across availability, confidentiality, and processing integrity.

NIST 800-53 Aligned

Aligned

Security controls aligned with NIST 800-53 federal information security guidelines.

HIPAA / HITECH Aligned

Aligned

BAA available. PHI handling safeguards for healthcare workflows including encryption, access controls, and audit trails.

TX-RAMP

Certified

Certified for the Texas Risk and Authorization Management Program, meeting state cloud security requirements for Texas agencies.

Authentication & Access

Single Sign-On (SSO)

SAML 2.0 and OAuth integration with Azure AD, Okta, Google Workspace, and other identity providers

Multi-Factor Authentication

Enforce MFA for all users or specific roles. Supports authenticator apps, SMS, and hardware tokens

Role-Based Access Control

Granular permissions by role, department, location, or project. Principle of least privilege enforced

Device Management

Approve/revoke devices remotely. Pin lock enforcement. Automatic session timeout. Remote wipe capability

Data Protection

Encryption at Rest

AES-256 encryption for all stored data, documents, photos, and form submissions

Encryption in Transit

TLS 1.2+ for all data transmission. Certificate pinning on mobile applications

Data Residency

US-based data centers. Data sovereignty controls available for government and regulated industries

Backup & Recovery

Automated daily backups with geo-redundant storage. Point-in-time recovery. 99.9% uptime SLA

Audit & Compliance

Complete Audit Trail

Every action logged — form submissions, edits, approvals, login events, admin changes. Immutable and exportable

Tamper-Evident Records

Digital signatures, timestamps, GPS coordinates, and photo metadata create verifiable, court-admissible records

Retention Policies

Configurable data retention rules by form type. Automated purging with compliance holds

Compliance Reporting

Pre-built reports for OSHA, EPA, state regulatory agencies, and internal compliance teams

Architecture

Security at every layer

Mobile Layer
iOS & Android native apps
Full offline data store
Local encryption (AES-256)
Biometric + PIN lock
Automatic sync queue
Application Layer
Load-balanced API gateway
Microservices architecture
Real-time event processing
Workflow engine
Integration middleware
Data Layer
Encrypted database clusters
Document & image storage
Geo-redundant backups
Audit log datastore
Analytics data warehouse
Security FAQ

Common security questions

Need security documentation?

Request our SOC 2 report, security questionnaire responses, or schedule a call with our security team.