Last updated · February 24, 2026
How we handle
your data.
Field Radar is used by property management companies, contractors, and enterprise field crews to run daily operations. Here's the honest, current-state picture of our security posture — no marketing, no vague claims.
Encryption
- TLS 1.3 in transit — every request, no exceptions
- AES-256 at rest on all databases and object storage
- Certificate pinning on the auth flow (SSL inspection carve-out required — see IT setup)
- Passwords hashed with bcrypt (cost factor 12)
Data Handling
- US-based hosting — data does not leave North America
- Per-tenant logical isolation — every query is filtered by
tenant_id - No customer data used for AI model training
- Delete on request within 30 days, verifiable audit log
Network
- HTTPS-only over TCP 443 · WebSocket upgrades allowed
- No inbound firewall requirements for customer networks
- Public IP allowlist available on request for enterprise customers
- Cloudflare in front — DDoS + WAF + global CDN
Compliance Roadmap
- SOC 2 Type 1 · in progress · target Q3 2026
- GDPR + CCPA-aligned data subject rights
- SAML SSO + SCIM · roadmap · Q4 2026
- HIPAA — not currently, not on roadmap. Do not upload PHI.
Availability
- Target uptime · 99.9% (8.7h downtime/year)
- Automated backups every 6 hours · 30 day retention
- Public status page · status.fieldradar.pro
- Incident postmortems published within 5 business days
Access & Auth
- Role-based access — admin / office / worker / read-only
- Multi-tenant row-level filtering on every query
- Session tokens rotated on password change / device change
- Push notification tokens per device, revocable individually
For corporate IT teams
If your office firewall or web filter is blocking Field Radar, hand your IT team the one-pager below. It contains the exact hostnames, protocol requirements, filter-vendor submission links, and SSL-inspection carve-out language they need.
Report a vulnerability
Found a security issue? Email security@fieldradar.pro with reproduction steps. We acknowledge within 24 hours and do not pursue legal action against good-faith researchers who give us reasonable time to fix.