Security
FIELD is built for sites where data separation and access control matter. Here's an overview of how we protect the platform and the data on it.
Last updated: Placeholder — pending legal review1. Infrastructure & hosting
FIELD is hosted on cloud infrastructure in Australia. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Backups are encrypted and access to production infrastructure is restricted to authorised engineers.
2. Multi-tenancy & data isolation
FIELD is multi-tenant by design, with strict data separation between operations. A technician or manager can only see data scoped to their tenant and role.
3. Access control
- Role-scoped permissions for technicians, managers and remote experts.
- SSO/SAML available on Enterprise plans.
- Enforced password policies and session expiry.
4. Audit logging
Every question asked, document approved and answer given is attributable and exportable. Admins get a full audit trail through the FIELD portal.
5. Approval-gated knowledge
Manuals, service bulletins and known issues only reach technicians after approval — nothing unreviewed reaches the field.
6. Compliance
QuipTech aligns its controls with SOC 2 Type II. Compliance reports and certifications are available to enterprise customers under NDA.
7. Vulnerability management
We run regular vulnerability scanning and engage third-party penetration testers on a periodic basis. Findings are triaged and remediated against defined severity timelines.
8. Incident response
We maintain an incident response process covering detection, containment, customer notification and post-incident review.
9. Reporting a vulnerability
Found a security issue? Email security@quiptechfield.com. We follow responsible disclosure and will acknowledge reports within a reasonable timeframe.
