The Platform · Posture
Everything below is either running on your instance today, or labelled as something that isn't yet. There is no third column for things we'd like you to assume.
A vendor security page is usually written to end the conversation. This one is written to survive it — because you are trusting a small shop with your customer list, and you should be asking hard questions rather than reading a badge.
So every item carries one of three labels, and we hold ourselves to them. If something moves from planned to live, this page changes. If it doesn't move for a year, it sits here saying so.
The three labels
Running on your instance now. You can ask us to show you.
Built and being turned on instance by instance. Not yet everywhere, and we'll tell you where yours stands.
Designed, not built. Listed here so you can weigh it, rather than discovering the gap later.
Separate application, separate database, separate backups. Your records are not a row in a shared table with a company ID beside them. This is the single biggest structural difference between us and a platform running thousands of businesses out of one database.
Your crew and your customers can sign in at your address rather than a shared portal with your logo dropped in the corner — on a domain registered in your name, not ours. It's a decision we put in front of you at onboarding and it stays yours to make. Shops running today started on a fieldamigo.com subdomain because it was quicker to stand up, and switching later is a DNS record and a certificate, not a migration. Ask whenever you want it.
The site you're reading loads no trackers, no analytics and no advertising pixels, and sets no cookies. Fonts are served from this server rather than a font network. We can say "no third-party requests" because it's literally true, not because we tuned a consent banner. The one thing it does store on your device is a single flag remembering you've already seen the opening animation, so it doesn't replay — it's discarded when you close the tab, and it identifies nothing.
Admin, dispatcher, sales and technician. A technician reaches customer details only for the jobs assigned to them — the full customer list isn't a URL away from a phone in a parking lot.
Optional authenticator-app codes. The seed is encrypted where it's stored, so the database only ever holds ciphertext for it.
Technicians get a signed, single-use link that expires, a device that remembers them afterwards, and an optional PIN that refuses obvious combinations and locks out after repeated wrong tries. No shared crew password on a whiteboard.
Portal pages tell search engines not to index them, browsers not to cache or store them, and other sites nothing about where the visitor came from — so a private link can't ride along in a referrer header to somebody else's server.
The application can read and write your records but cannot change the schema, create accounts, or reach any other database. Standard on every new build, not an upgrade — so a flaw in the application has a much smaller blast radius than the database itself.
Each signed checklist is chained to the one before it with a key held by the application and never stored in the database — so database access alone can't forge history. How that works.
Ledger entries are append-only, enforced by the database rather than by app code. A correction writes a reversal and a repost; nothing is edited away. How that works.
One click gathers every record about a single person from across the whole system, with a list of their files. For a subject-access request, or just to answer them honestly when they ask.
Built, and being turned on one instance at a time starting in report-only mode — the browser reports what an enforcing policy would break without blocking anything, so we find the breakage before your crew does. It is not enforcing anywhere yet, and we won't switch an instance to enforcing until its report log is quiet. Ask us where yours stands.
Traffic between the application and its database is currently password-authenticated inside a private network on the same host. Encrypting that hop as well is on the list and is not done.
Consent capture and full export ship today. Erase-on-request is designed and not yet built. We'd rather say so than let you assume it.
A verified copy every day on the server, and an encrypted copy every day somewhere else entirely. One of those protects you from a mistake; the other protects you from losing the machine.
Offsite copies are encrypted to a key whose private half is kept offline — the server only holds the public half. Someone who takes the machine gets the backups and cannot open them.
We rebuild instances from backups as a drill rather than waiting to find out during an emergency — a complete, working copy we can sign into and read. Your files, photos, receipts and signed documents, are proven by a separate drill, deliberately: copying every document across just to rehearse a restore moves an enormous amount of data for an answer we can get on its own. A backup nobody has ever restored is a hope, not a backup.
The whole database exports from the settings screen, and a copy is emailed to you on the first of every month through a single-use link, whether you asked or not. The full continuity plan.
Every push runs security linting and a dependency audit, and known-vulnerable packages are flagged automatically. Where we accept a risk temporarily, the exception carries an expiry date rather than being switched off.
No badge, and we're not going to imply one
No SOC 2. No ISO 27001. No third-party penetration test. Those cost tens of thousands of dollars a year and we are a small shop; pretending otherwise would be the first lie on this page, and it would be a strange one to tell right underneath a list of things we do carefully.
Cyber / professional liability insurance is quoted and ready, not yet bound. We priced a policy before this platform ever took on a client's real QuickBooks connection, and it activates before that connection goes live — currently on standby because there isn't a client requiring it yet, not because it isn't ready.
What that means for you. If your business or your customers require a vendor with a completed audit — some commercial and municipal contracts do — we are not that vendor today, and you should know it before you sign rather than during a procurement review. Say so on the call and we'll tell you straight.
Support is us, in Tampa, in business hours. Fast and genuinely personal, but there is no 24/7 desk and no on-call rotation. See the note for larger operations, where this matters most.
No security is absolute. Anyone who tells you their software cannot be breached is selling something. What we can tell you is where your data sits, who can reach it, what happens when a machine dies, and which items on this page aren't finished.
This page is maintained by hand and dated by its changes. If something here has gone
stale or you think a label is generous, tell us — [email protected].
That's a real invitation.
Where does my data physically sit? Who at your company can read my customer list? What happens the day you get hit by a bus? All fair, all answerable on a thirty-minute call.
Email: [email protected] · Fieldamigo LLC, Tampa, Florida