Your field data — customer records, job photos, signatures, safety documentation — is the operating record of your business. Here is precisely how we secure it, who we share it with, and what we're still improving.
All traffic runs over HTTPS with HSTS enforced for a year across every subdomain. Database storage is encrypted at rest by our database provider, and traffic between our application and database is TLS-encrypted.
Passwords are hashed with bcrypt and individually salted — we can never read them. A strength policy is enforced by the server, not just the browser. Sessions use short-lived access tokens. Password-reset and email-verification links are high-entropy, expire, and are destroyed the moment they're used.
Five roles — Administrator, Manager, Form Designer, Reporter, and Field Technician — each mapped to an explicit set of capabilities. Permissions are deny-by-default: a role gets nothing it hasn't been granted, so a new role can never inherit access by accident.
Every query in the application is scoped to your company, including file downloads. This isn't a convention we hope developers follow — it's covered by automated tests that fail the build if one company can ever read another's records.
Rate limits protect every credential surface: sign-up, sign-in, customer-portal login, and magic links. Security headers (frame-denial, MIME-sniffing protection, referrer and permissions policy) ship on every response. Customer portal codes are stored hashed and compared in constant time; API keys are stored hashed and shown only once.
Uploads are restricted to an allowlist of document and image types with a size cap. Filenames are generated by the server, never taken from the uploader, which removes an entire class of path-traversal attack. Downloads re-check that the file belongs to your company before a single byte is served.
Every change moves through version control and an automated test suite of 1,300+ tests before it can reach production. Dependencies are scanned for known vulnerabilities and patched on a regular cadence. No credentials are ever stored in our source code.
Security-relevant events — sign-ins and failed sign-ins, permission changes, data exports, external access grants, and API key lifecycle — are recorded with timestamp, user, and IP address, and are reviewable by your administrators.
Export anytime. Every account can download its complete data — customers, jobs, forms, submissions, and files — in open formats, without asking us and without a support ticket. We built this deliberately: software that holds your data hostage isn't a partner.
Delete on your terms. You can cancel and delete your account yourself from inside the product. We don't require a phone call to let you leave.
We don't sell your data, and we don't train AI models on it. Your records are used to provide the service to you — nothing else. The optional AI assistant only sees what you explicitly send it.
The third parties that process data on our behalf. Services marked optional only receive data if you turn that feature on.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Railway | Application hosting | All application data in transit and processing | United States |
| MongoDB Atlas | Primary database | Customer records, forms, submissions, users | United States |
| Cloudflare | DNS, CDN, DDoS protection | Network traffic metadata | Global |
| Resend | Transactional email | Email addresses and message content | United States |
| StripeOnly when you buy a plan | Subscription billing | Billing contact and payment details (card data never touches our servers) | United States |
| Sentry | Error monitoring | Stack traces and request metadata from application errors; no form answers | United States |
| Cloudflare R2 | File and photo storage | Uploaded photos, signatures, documents | United States |
| TwilioOnly if enabled | SMS notifications | Phone numbers and message content | United States |
| AnthropicOnly if enabled | AI assistant | Prompt content you submit to the assistant | United States |
| Intuit QuickBooksOnly if enabled | Accounting sync | Invoice and customer records you choose to sync | United States |
| GitHub | Source code hosting and CI | Source code and CI logs — no customer data | United States |
| Google (Gmail SMTP)Fallback only | Fallback transactional email | Email addresses and message content, only if Resend is not configured | United States |
Field Wizard has not completed a SOC 2 audit, and we will not imply otherwise. What we have done is map our controls to the SOC 2 Trust Services Criteria and maintain the underlying practices and documentation — access control, change management, vulnerability management, incident response, and data retention — so that a formal examination is a process step rather than a rebuild. When that examination is complete, this page will say so plainly.
We support GDPR and CCPA data-subject requests (access, export, correction, deletion) through the same self-serve tools described above. A Data Processing Agreement is available on request.
Published because a security page that lists only strengths isn't worth reading.
Email security@gofieldwizard.com. We investigate every report, respond within two business days, and will never pursue legal action against good-faith research.
Email security@gofieldwizard.com for our security policy, subprocessor list, incident response plan, or a completed vendor questionnaire.
Email privacy@gofieldwizard.com to access, correct, export, or delete personal data we hold.
Start a free trial, open it in the builder, and send it to a technician today. No card required.
Start free trial →30 days free · no card · cancel yourself any time. No seat minimum.
Would rather ask a person first? Email us — a human answers.