Security you can audit, not just read about

Isolation, access, audit and encryption designed in, and controls you can verify.

Controls by domain

Isolation

One database per tenant, no shared transactional tables, scoped signed URLs, and region-bound backups.

Identity and access

Microsoft Entra ID (OIDC) plus forms auth, enforceable MFA, and RBAC by role, module and level with per-user overrides. SSO and SAML with Okta and Google Workspace.

Audit

Append-only per-tenant audit with before and after and a reason, login audit with IP and location, and immutable finalised documents.

Support access governance

Impersonation only with a ticket, a reason and a bounded duration; it auto-expires and is always logged.

Encryption and data protection

TLS 1.2+, encryption at rest for databases, backups and objects, envelope-encrypted integration secrets, masked Aadhaar, and encrypted offline payloads with remote wipe.

Backups and disaster recovery

Daily per-tenant backups, point-in-time recovery, 30, 60 or 90-day retention, in-region by default with cross-region opt-in.

Retention

Seven years for transactions, documents and audit; two years for login audit; a 30-day soft delete.

Compliance posture

GST-compliant invoicing and returns, per-tenant data residency, a WCAG 2.1 AA target, and a secure SDLC. FieldDNA operates SOC 2 Type II- and ISO 27001-aligned controls.

Responsible disclosure

Found something? Our security contact is published at /.well-known/security.txt, and reports go to security@fielddna.com.

Frequently asked questions

Is FieldDNA SOC 2 or ISO 27001 certified?

FieldDNA operates SOC 2 Type II- and ISO 27001-aligned controls. We do not claim a certification until an independent audit report exists.

Where is our data stored?

In your isolated tenant database in your chosen region, with in-region backups by default and cross-region as an opt-in.

How is support access controlled?

Support can only access a tenant with a ticket, a stated reason and a time limit; access auto-expires and every action is logged.

How do you report a vulnerability?

See /.well-known/security.txt; reports go to security@fielddna.com.

Ready to run your distribution chain from one platform?

Live walkthrough on Microsoft Teams · Tailored to your distribution model · Works on web, Android and iOS