Built to Pass Your Security Review
Encryption, isolation, SSO, device revocation, and credential hashing — in one place. This is the page to send your security team.
What Protects Your Data
Encryption at Rest on Every Device
Data captured in the field is encrypted on the device with AES-256, with keys held in the platform secure enclave — iOS Keychain and Android KeyStore.
Full Multi-Tenant Isolation
Built as secure multi-tenant SaaS from day one. Each customer's data is fully isolated — one customer's data is never visible to another.
Microsoft Entra ID SSO
Sign in with your existing Microsoft Entra ID (Azure AD) identity, alongside passwordless magic-link and email/password options.
Session & Device Control
Every session is tied to a device. Admins see all active devices and can revoke any of them instantly; deactivating a user signs them out automatically, everywhere.
Hashed Credentials & Tokens
Credentials and tokens are stored hashed — a database leak exposes no usable secrets.
Write-Once, Attributed Evidence
Every capture is write-once and stamped with who, what device, when, where, and which form version — a tamper-evident record for compliance and disputes.
Put Us in Front of Your Security Team
We'll walk your IT and security reviewers through the architecture — identity, encryption, isolation, and device control — and answer the questionnaire items directly.
- Microsoft Entra ID (Azure AD) SSO
- AES-256 encryption at rest on devices
- Instant device revocation
Security FAQ
Straight answers for your IT and security reviewers.
We don't claim certifications we can't show you. The platform provides the security architecture described on this page — encryption at rest, tenant isolation, SSO, device revocation, hashed credentials — and the tooling to support your GDPR and audit obligations. Ask us for the current status of formal attestations for your review.
Revoke that device's access instantly from the admin portal. Data on the device is encrypted at rest with AES-256, and each session is tied to the specific device, so revocation is immediate and targeted.
A built-in PII erasure workflow anonymizes a person on request while preserving business-record integrity, supporting the "right to be forgotten." Tenant isolation and the attributed evidence trail support your broader accountability obligations. See our GDPR page for detail.
On Microsoft Azure — serverless functions, SQL, and blob storage — built cloud-native for scale and reliability. See Platform & Scale for more.
