Skip to content

Document security built for enterprise procurement reviews.

Invoices, claims, and regulatory filings carry financial and operational data that your security team will ask about before signing. This page covers what we've built, where we are on SOC 2, and what we can document for your vendor review.

What we've built — controls your IT team will ask about

AES-256 at rest. TLS 1.3 in transit. SSO/SAML 2.0. Per-customer key management. Tamper-evident audit logs. Configurable retention from 30 days to 7 years. These are the controls that show up on every SIG and CAIQ questionnaire.

Data Encryption
Documents and extracted data are encrypted at rest using AES-256. All data in transit uses TLS 1.3. Encryption keys are managed per-customer in a dedicated key management service with rotation schedules configurable to your policy.
Access Controls
SSO and SAML 2.0 federation supported on Growth and Enterprise plans. Role-based access control with configurable permissions per document type and workflow queue. MFA enforced for all platform access. Service-to-service API authentication via scoped token issuance.
Data Retention
Default 90-day auto-deletion of original documents after extraction completes. Extracted data (structured JSON fields) is retained per your configured policy — from 30 days to 7 years. On-demand deletion API for individual documents or full customer datasets on request.
Audit Logging
Comprehensive audit log of every document submission, extraction result, exception routing event, and user access action. Log export available in JSON or SIEM-compatible format. Log retention is configurable and tied to your data retention policy. Tamper-evident append-only design.

Our compliance posture — written plainly, no inflated badge claims

This is where Fieldiq's controls actually stand. We don't claim certifications we haven't completed. If a vendor requires a badge we haven't earned yet, we'll tell you that directly and offer compensating controls documentation.

SOC 2 Type II — In progress
We are building toward SOC 2 Type II certification. Our current controls align with SOC 2 Trust Service Criteria for Security and Availability. We are targeting audit initiation within the next audit cycle. Customers requiring SOC 2 Type II today should engage our Enterprise plan and we will work with your procurement team on compensating controls documentation.
HIPAA-aware handling — Available on Enterprise
Healthcare customers processing documents containing PHI (Protected Health Information) can engage HIPAA-aware data handling on Enterprise plans. This includes BAA (Business Associate Agreement) execution, PHI-scoped access controls, and dedicated processing infrastructure that does not co-mingle PHI with non-PHI workloads. We do not process healthcare clinical records outside this configuration.
GDPR and US State Privacy Laws
Fieldiq operates under Texas law and complies with the Texas Data Privacy and Security Act (TDPSA). Standard Data Processing Agreement (DPA) available for customers with EU/EEA data subjects. California CCPA obligations addressed in our Privacy Policy. Data minimization: we extract only the fields you configure — no retention of extracted data beyond your configured window.

Have a vendor security questionnaire?

We complete standard security questionnaires (SIG, CAIQ, custom) on Enterprise plans. Contact us with your questionnaire and we'll scope the completion timeline.

Request security questionnaire response

Security questionnaire? We'll complete it.

We complete SIG, CAIQ, and custom vendor questionnaires on Enterprise plans. Contact us with your questionnaire — we'll give you a completion timeline and flag anything that requires compensating controls discussion before you get surprised in procurement review.