Encryption
TLS 1.2+ in transit. Data at rest encrypted by Firebase/Google Cloud managed keys.

fieldGRID is built on Google Cloud (Firebase) with security enforced at the database layer. Our goal is simple: keep your company’s data isolated, encrypted, and auditable.
TLS 1.2+ in transit. Data at rest encrypted by Firebase/Google Cloud managed keys.
Role-based access (admin/manager/payroll manager/member) with strict per-company Firestore rules.
Immutable events for approvals and key changes. Read-only Audit Log UI.
Automated backups and documented RPO/RTO with restoration tests.
Company export & deletion on request; admin-configurable retention for selected modules.
Offline queue with auth required for sensitive ops; tokens revocable server-side.
Dependency monitoring, regular updates, and third-party pen-tests on the roadmap.
Health checks, error tracking, background retries for uploads/sync.
We’re formalizing controls and collecting evidence toward third-party certifications. If your organization needs specific attestations, we can align timelines.
Initial attestation after controls + evidence.
Annual audits after 6–12 months of operating controls.
ISMS formalization, risk register, internal + surveillance audits.
Okta & Microsoft Entra ID; SCIM provisioning.
EU-hosted by default; regional options as Firebase/GCP allow.
Standard DPA and published subprocessors list.
Google Cloud (Firestore/Storage). EU hosting prioritized where possible.
Yes. Admins can request export and deletion; legal hold available on request.
Okta/Microsoft Entra SSO on the near-term roadmap. Request pilot access.
Documented incident response with triage SLAs, customer notification, and postmortems.
We’re happy to share our security one-pager, DPA, and architecture notes, or to set up a technical review with your IT team.