Legal
Security
Version 2026-09-23. Effective 2026-09-23. This is a product template for legal review, not legal advice.
Current practices
FieldKeel is built as a multi-tenant operations product. The following controls are implemented in the current application. We do not claim that any system is completely secure.
- HTTPS is expected in production deployments
- HTTP-only session cookies; tokens are not stored in browser storage
- Password hashing
- Role-based organization authorization
- Organization-scoped queries and tenant isolation tests
- Private object storage with authorized file access
- Audit logging of sensitive actions
- Server-side validation and authentication rate limiting
- Least-privilege checks on platform versus tenant APIs
What we do not claim
This page does not list SOC 2, ISO, HIPAA, or other certifications. Backup and hosting-region statements will be added when a production strategy is actually configured.
Report a security concern
Email security@fieldkeel.local. Include enough detail for us to reproduce the issue. Do not include customer passwords or payment credentials.
Related: Trust Center and Privacy Policy.
Questions: support@fieldkeel.local