Security
Your trust is our foundation. We protect your data with enterprise-grade security practices.
Data Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256)
Secure Infrastructure
Hosted on DigitalOcean with SOC 2 Type II certified data centers
Tenant Isolation
Complete data separation between business accounts at the database level
24/7 Monitoring
Continuous security monitoring and automated threat detection
Our Security Commitment
At ForemanIQ, security is not an afterthought — it's built into every layer of our platform. We understand that you're trusting us with sensitive business data, and we take that responsibility seriously.
Infrastructure Security
Cloud Hosting
ForemanIQ is hosted on DigitalOcean's secure cloud infrastructure, which provides:
- SOC 2 Type II certified data centers
- Physical security with 24/7 monitoring
- Redundant power, cooling, and network connectivity
- Regular third-party security audits
Network Security
- DDoS protection and mitigation
- Web Application Firewall (WAF)
- Intrusion detection systems
- Regular vulnerability scanning
Data Protection
Encryption
We protect your data with strong encryption:
- In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3
- At Rest: Data stored in our databases and file storage is encrypted using AES-256 encryption
- Backups: All backups are encrypted and stored securely
Multi-Tenant Isolation
ForemanIQ is a multi-tenant platform, meaning multiple businesses use the same infrastructure. We enforce strict data isolation:
- Database-level isolation ensures your data is never accessible to other tenants
- Application-layer security verifies tenant context on every request
- Regular audits verify isolation effectiveness
Data Backups
- Automated daily backups of all data
- Backups stored in geographically separate locations
- Regular backup restoration testing
- 30-day backup retention
Application Security
Authentication
- Secure password hashing using bcrypt
- Session management with secure, httpOnly cookies
- CSRF protection on all forms
- Rate limiting to prevent brute force attacks
Access Control
- Role-based access control (Owner, Office Staff, Field Crew)
- Principle of least privilege enforced
- Activity logging for audit trails
Secure Development
- Security-focused code reviews
- Automated security testing in CI/CD pipeline
- Regular dependency updates and vulnerability patching
- OWASP Top 10 protection (XSS, SQL injection, CSRF, etc.)
Monitoring and Response
Continuous Monitoring
- 24/7 automated monitoring for security anomalies
- Real-time alerting for suspicious activity
- Centralized logging with Sentry for error tracking
Incident Response
We maintain an incident response plan that includes:
- Defined roles and escalation procedures
- Communication protocols for affected users
- Post-incident analysis and remediation
Compliance
We design ForemanIQ with compliance in mind:
- GDPR-ready data handling practices
- CCPA compliance for California residents
- PCI-DSS compliant payment processing (via Stripe)
Responsible Disclosure
We believe in the value of security research. If you discover a security vulnerability in ForemanIQ, please report it responsibly:
- Email: [email protected]
- Include details about the vulnerability and steps to reproduce
- Give us reasonable time to investigate and fix before disclosure
- We will acknowledge your report within 48 hours
We do not pursue legal action against security researchers acting in good faith.
Your Security Responsibilities
Security is a shared responsibility. We recommend that you:
- Use strong, unique passwords for your ForemanIQ account
- Keep your login credentials confidential
- Log out of shared or public devices
- Report any suspicious activity to our support team
- Keep your team members' access levels appropriate to their roles
Contact Us
For security questions or to report a concern:
- Security issues: [email protected]
- General support: Contact Form