Security

Designed for sensitive multi-tenant operational data.

FieldAssets will be built around tenant isolation, client data scopes, MFA, audit logs, secure sessions, and transaction-level access.

Identity and MFA

Central login, authenticator app first, email OTP second, WhatsApp OTP fallback, and secure production session handling.

Access control

Platform, tenant, client, role, transaction, and data visibility checks before any sensitive action.

Auditability

Login, logout, failed login, MFA, password reset, user, role, permission, configuration, and support access events.

Compliance direction

Architecture aligned to ISO 27001, SOC 2, OWASP, NIST, CIS Controls, POPIA, and GDPR principles.