FieldNotch stores work orders, payroll records, employee data, and financials for subcontractor businesses. We treat that like the responsibility it is.
The controls behind the marketing words. Specific, current, and honest about what's in place versus what's on the roadmap.
Strong encryption everywhere data lives or moves.
TLS 1.3 for all traffic between your browser, our APIs, and mobile appsAES-256 at rest for Postgres, file storage, and encrypted nightly backupsYour business data is logically separated from every other customer.
Row-Level Security policies on every tenant-scoped tableorg_id by the application layer AND the database layerLayered protection against unauthorized account access.
bcrypt (cost factor 12), never stored in plain textInternal access to production is narrow and audited.
Hardened hosting on EU-based, ISO 27001 / SOC 2 compliant providers.
Security is baked into how we build, not bolted on after.
Dependabot) — critical CVEs patched within 48 hoursSemgrep, CodeQL)Every meaningful action is recorded, attributable, and retrievable.
Your data survives the bad days.
Honest snapshot of what's complete, in progress, and planned. We update this page when a status changes.
Audit engaged with a Big 4 affiliate firm. Type I report targeted Q3 2026, Type II report Q1 2027. Letter of engagement available under NDA.
Standard Contractual Clauses with EEA sub-processors. DPA available to all customers on request. Designated EU representative if required.
California-resident rights respected — access, deletion, correction, opt-out from selling (we don't sell), and limit-use rights for sensitive data.
Canadian Personal Information Protection and Electronic Documents Act compliance for our Canadian customers.
FieldNotch never sees credit card numbers — all payments are tokenized and handled by Stripe, a PCI Level 1 service provider.
Not applicable today — FieldNotch isn't designed for protected health information. Will revisit if customer demand emerges (e.g., HVAC subs for hospitals).
Backed by our Terms of Service and Privacy Policy, not just marketing copy.
Ever. Not aggregated, not "anonymized," not as part of a partnership deal. Your business data exists in FieldNotch only to serve you.
Our AI provider (Groq) is contractually prohibited from training models on Your Content. The work orders, employee records, photos, and notes you upload stay yours.
Internal access to customer data is restricted to a narrow set of engineers, requires named authentication, is logged, and is reviewed quarterly. We don't browse your data for fun.
Export everything — work orders, employees, invoices, payroll, audit logs — in CSV, PDF, and JSON formats. Available while subscribed, and for 30 days after cancellation.
Most account compromises happen because of weak passwords, missing 2FA, or stale permissions — things we can give you tools to manage but can't fix for you.
FieldNotch welcomes security research and responsible disclosure. If you've found a vulnerability — even one you're not sure about — please report it before sharing publicly. We'll respond within one business day.