Security at every layer
From device to database, every connection and every byte is protected.
🔒

Data at Rest

All data stored in Google Cloud Firestore is encrypted at rest using AES-256 encryption, managed by Google's infrastructure. Encryption keys are rotated automatically. Your business data is never stored in plain text.

🔐

Data in Transit

Every connection between your device and our servers uses TLS 1.2+ (HTTPS). All API calls, file uploads, and data syncs are encrypted end-to-end. No data is ever transmitted unencrypted.

👤

Authentication

User authentication is handled by Firebase Authentication with bcrypt password hashing, secure session tokens, and automatic token rotation. Support for email/password and Apple Sign-In.

💳

Payment Security

All payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor. FieldForge never stores, processes, or has access to credit card numbers. Payment data goes directly to Stripe.

🖥

API Security

All API calls are made server-side through Firebase Cloud Functions. No API keys, secrets, or service credentials are stored on the device. Server-side validation on every request.

Compliance

FieldForge operates in compliance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). We collect only what is necessary and give you full control over your data.

How it all connects
A serverless architecture on Google Cloud means no servers to patch, no infrastructure to manage, and automatic scaling.
Client
iOS App
Auth
Firebase Auth
Compute
Cloud Functions
Database
Firestore
External Services
Payments
Stripe
Email
Resend
SMS
Twilio
Storage
Cloud Storage

Every external service communicates through authenticated, server-side Cloud Functions. No API keys or third-party credentials are ever exposed to the client device. All inter-service communication uses TLS encryption.

Privacy practices
We believe in transparency. Here is exactly how we handle your data.

Data Retention

Your data is retained for as long as your account is active. We do not sell, share, or monetise your business data. Inactive accounts are subject to our data retention policy outlined in our Privacy Policy.

Right to Deletion

You can delete your account and all associated data at any time from the app (Account > Danger Zone > Delete Account). Deletion is permanent and irreversible. All data is purged from our systems within 30 days.

Data Export

You can export your data at any time. Quotes, invoices, customer records, and compliance documents can all be exported as PDF or CSV files from within the app.

Minimal Collection

We collect only the data necessary to provide the service: your business details, customer information you enter, and usage analytics. We do not track your location or access your contacts.

Third-Party Data Sharing

Your data is shared only with the services required to operate FieldForge: Stripe (payments), Resend (email), and Twilio (SMS). Each service processes only the minimum data required for their function.

Breach Notification

In the unlikely event of a data breach, we will notify affected users within 72 hours as required by the Australian Privacy Act. We maintain incident response procedures and conduct regular security reviews.

Built on trusted infrastructure
Our technology partners maintain the highest security certifications in the industry.

Google Cloud Platform

SOC 1/2/3 certified, ISO 27001, ISO 27017, ISO 27018 compliant. Firebase infrastructure runs on Google's world-class data centres with 99.95% uptime SLA.

💳

Stripe PCI-DSS Level 1

Stripe is a PCI Service Provider Level 1 certified processor, the most stringent level of certification available. All card data is handled exclusively by Stripe.

🇦🇺

Australian Privacy Act 1988

We comply with the Australian Privacy Act 1988 and all 13 Australian Privacy Principles (APPs). Your rights as an Australian business operator are fully protected.

Questions?

Security is not optional. It is foundational.

Have security questions? Reach out to our team. We are happy to discuss our practices in detail.

Contact Security Team