Version: 1.0
Owner: InnOneWeb OĆ (support@fieldcosts.com) Review cycle: At least annually and after material system or risk changes.
This document describes the security controls FieldCosts commits to maintain for the Service, subject to the actual architecture and risk profile.
1. Security governance
FieldCosts will maintain:
- a designated security owner;
- documented security responsibilities;
- periodic risk assessments;
- written access, incident, retention, and backup procedures;
- review of material vendors and Subprocessors;
- security requirements in development and operations;
- annual review of this document.
2. Personnel security
FieldCosts will:
- limit access to personnel with a business need;
- require confidentiality obligations;
- provide security and privacy awareness training;
- remove access promptly after termination or role change;
- review privileged access periodically;
- require contractors with access to meet appropriate confidentiality and security requirements.
3. Identity and access management
Controls include:
- unique user accounts;
- role-based access controls;
- least-privilege access;
- separate privileged or administrative access where practicable;
- strong password requirements;
- multi-factor authentication for privileged and infrastructure access;
- session expiration and revocation;
- access logging;
- periodic review of administrative access;
- prompt removal of inactive or unauthorized access.
Customer administrators remain responsible for end-user roles and permissions in their own workspace.
4. Tenant and application security
FieldCosts will design the Service to:
- logically separate customer workspaces;
- enforce authorization server-side;
- validate access to Customer Content on each protected request;
- prevent predictable identifier access;
- validate and sanitize inputs;
- use CSRF protection where relevant;
- use secure cookie attributes;
- apply rate limiting or abuse protection to sensitive endpoints;
- avoid exposing secrets in client-side code;
- protect file access with authorization checks or time-limited access.
5. Encryption
FieldCosts will use:
- TLS for data in transit over public networks;
- encryption at rest where supported and appropriate for databases, object storage, and backups;
- secure password hashing using a modern adaptive algorithm;
- managed secret storage or equivalent controls for credentials and keys;
- restricted access to encryption keys and secrets.
Do not claim end-to-end encryption unless it is actually implemented.
6. Infrastructure and network security
Controls may include:
- production and non-production separation;
- firewalls and security groups;
- minimal exposed services;
- hardened server configuration;
- secure remote administration;
- malware and abuse protection where appropriate;
- infrastructure patching;
- vendor-supported components;
- denial-of-service and traffic protections appropriate to the deployment.
7. Secure development lifecycle
FieldCosts will maintain practices including:
- version control;
- code review for material changes;
- dependency and vulnerability review;
- separate development, testing, and production environments where practicable;
- secure configuration management;
- testing before production deployment;
- documented deployment and rollback procedures;
- prohibition on production secrets in source repositories;
- remediation of material security findings based on risk.
8. Vulnerability management
FieldCosts will:
- monitor relevant security advisories;
- maintain an inventory of material software components;
- apply security updates according to severity and operational risk;
- investigate credible vulnerability reports;
- periodically test public attack surfaces;
- track remediation to closure;
- perform penetration testing when proportionate to product maturity and risk.
Suggested remediation targets, subject to validation:
| Severity | Target |
|---|
| Critical actively exploitable | Immediate containment; remediation as soon as practicable |
| Critical | 7 days |
| High | 30 days |
| Medium | 90 days |
| Low | Risk-based |
9. Logging and monitoring
FieldCosts will maintain logs appropriate to:
- authentication;
- privilege changes;
- material administrative actions;
- security events;
- application errors;
- infrastructure events;
- data export or deletion where practicable.
Logs will be:
- access-restricted;
- protected from unauthorized modification where practicable;
- retained according to the Retention Policy;
- reviewed during incident investigation.
Passwords, full payment-card details, and unnecessary Customer Content must not be intentionally written to logs.
10. Backup, continuity, and recovery
FieldCosts will:
- maintain backups appropriate to the Service;
- protect backups against unauthorized access;
- separate backup credentials from ordinary application access where practicable;
- define backup frequency and retention;
- test restoration periodically;
- document recovery priorities and responsibilities;
- maintain procedures for significant service disruption.
- application database backup: an operator-configured daily task;
- application-managed backup retention: 30 days;
- organization export and closure grace period: 30 days;
- hosting-provider snapshots: governed by the hosting contract and isolated from ordinary application access;
- recovery point and recovery time: best effort unless an Order expressly states contractual RPO or RTO commitments.
11. Data minimization and deletion
FieldCosts will:
- collect only data reasonably needed for stated purposes;
- provide customer deletion and export functions where appropriate;
- apply documented retention periods;
- delete or anonymize data when no longer required;
- restrict access to retained legal-hold or backup data;
- ensure Subprocessors delete or return data under contract.
12. Subprocessor security
Before onboarding a material Subprocessor, FieldCosts will assess, as proportionate:
- security and privacy documentation;
- service location;
- breach history;
- certifications or independent reports;
- contract and DPA terms;
- transfer safeguards;
- access to Customer Personal Data;
- business continuity.
13. Incident response
FieldCosts will maintain:
- a reporting channel;
- severity classification;
- incident roles;
- evidence-preservation procedures;
- containment and recovery steps;
- legal notification assessment;
- customer communication procedures;
- post-incident review.
The Personal Data Breach Procedure is incorporated by reference.
14. Physical security
Physical controls are primarily provided by approved hosting and office providers.
FieldCosts will:
- restrict access to company devices;
- use device lock and encryption where supported;
- avoid unnecessary local storage of Customer Content;
- securely dispose of devices and media;
- require reasonable physical protection for remote work.
15. Customer responsibilities
Customers must:
- use secure passwords and devices;
- configure roles appropriately;
- enable available security features;
- remove former users;
- control integrations;
- review suspicious activity;
- keep independent records where required;
- notify FieldCosts promptly of suspected compromise.
16. Retention and lifecycle operations
FieldCosts uses bounded scheduled jobs for public analytics cleanup, WhatsApp raw-payload scrubbing, expired organization-record cleanup, application-backup pruning, and final erasure of workspaces whose 30-day closure period has ended. A documented workspace legal hold pauses scheduled record cleanup and final deletion until an authorized platform owner releases it.