Security Architecture & Controls
The local candidate has passed automated checks. Production configuration and live acceptance remain incomplete.
HTTPS deployment requirement
Production deployment must verify HTTPS, provider storage settings and data locations. No specific encryption algorithm or hosting region is certified by this page. Local drafts are readable browser data on the device.
Database Rules & IAM
Firestore and Storage rules require an active operator membership for the requested organization. These controls reduce cross-tenant access risk but do not replace testing, monitoring, or incident response.
1. Cloud Infrastructure & Hosting Hardening
The candidate targets Firebase Auth, Firestore, Storage and Functions. Hosting headers and organization access checks exist in the repository, but deployed settings must be verified before customer onboarding. FieldLedger does not claim a SOC 2 report, ISO certification or an independent security assessment.
2. Offline Data Storage & Sync Security
Checklist drafts and pending photos are stored in IndexedDB on the device. FieldLedger does not add application-level encryption to that local storage. Reconnect to upload evidence and finalize a visit; signing out clears local drafts. Use device access controls and avoid shared devices for customer information.
3. Vulnerability Disclosure & Bug Reporting
A monitored security contact and incident owner must be confirmed before customer onboarding. No response-time commitment or unverified reporting address is published here.