Security

How we protect your data

Fieldwork is built on secure infrastructure. This page describes the specific controls in place across our application, data handling, and access model.

Last security review: 2026-08-21


Infrastructure

  • Australian data residency. The database, file storage, authentication, and server-side application compute all run in AWS ap-southeast-2 (Sydney). Interview transcripts and participant records are stored in Australia. Interview messages are sent to Anthropic in the US while a session is active. See the data handling page for the full sub-processor list.
  • Encrypted transport and storage. All connections use TLS. Data at rest is encrypted using AES-256 via AWS-managed controls.
  • Restricted production access. Access to production systems is limited to authorised team members and logged.
  • Network isolation. Application, database, and storage layers are isolated through managed cloud controls.

Application security

  • Strict workspace separation. Each workspace's interviews and transcripts are only visible to people you add there. Boundaries are enforced in the database as well as in the application.
  • Passwordless authentication. Sign-in uses magic links; no password database exists for credential stuffing attacks.
  • Rate limiting and abuse controls. Automated limits protect interview and AI endpoints from overload and misuse.
  • Scoped background processing. Summaries, exports, and billing jobs are tied to a single workspace so work cannot leak across customers.
  • Origin allow-list for in-product interviews. The key you put in your page is meant to be public, so it is bound to the sites you name. A copy of it lifted from your source runs nowhere else.
  • Disclosure before any interview. Participants are told they are talking to an AI, what is collected, and that their answers do not train AI models. No interview turn runs until they accept.
  • Attributed interview surface. Every interview carries the name of the company doing the research, so a window that opens inside a product cannot be mistaken for an anonymous prompt asking for personal information. Logos are accepted over https only.
  • Nothing asks during a cancellation. Every site ships with cancellation, refund and downgrade paths blocked, and the block is checked before any setting on the moment, so nothing can switch it back on for those pages.
  • Declining lasts. Someone who asks not to be contacted again is recorded against the whole site rather than the one study, permanently, and it is checked before anything else. Researchers cannot see or clear that list.
  • The same rules when there is no browser. Interviews triggered from a customer's own servers go through the identical checks in the identical order, and are handed out as a single-use link tied to one person that expires. Declining and the contact interval apply there too, so which door an interview arrived through changes nothing about who gets asked.
  • We only keep the context you named. Data a customer's site sends along with an interview is discarded unless they declared that field in advance, and what we keep is the group rather than the value: a number becomes a range, and anything outside a declared list is recorded as other. A field holding an email address or a phone number cannot survive that, so this is not somewhere personal information can collect by accident.
  • What we send back never includes what was said. A customer can ask us to notify their own systems when an interview finishes. That notification carries the fact of it, the context they gave us and a reference they chose, so they can join it to their records. It does not carry the transcript or a summary of one. Someone agreed to take part in research, not to have their answers land on a sales record, so interview content stays in Fieldwork.
  • Secret keys are stored as hashes. A key for the server API is shown once, when it is created, and only its hash is kept. We cannot recover one, which means a copy of our database is not a set of working credentials. Keys are limited to workspace owners and can be revoked at any time.
  • Enterprise SSO support. Enterprise plans can enable SSO through their identity provider.

Certifications (via sub-processors)

SOC 2 Type II

Database & auth (AWS)

SOC 2 Type II

Application hosting

PCI DSS Level 1

Stripe

ISO 27001

AWS


Current limitations

We are direct about what we do not yet have.

  • SOC 2 certification (Fieldwork). Our infrastructure sub-processors are SOC 2 certified. We will pursue our own audit as the business scales.
  • Independent penetration test. Not yet commissioned. Planned before targeting enterprise customers at scale.
  • TOTP 2FA. Magic link authentication removes password-based attack vectors. A separate TOTP option is not currently available.

Responsible disclosure

If you discover a vulnerability, email hello@dofieldwork.io with details and reproduction steps. We acknowledge reports within 3 business days and aim to resolve confirmed issues within 30 days.

Last updated: 2026-08-21 · Questions: hello@dofieldwork.io · Locallabs Pty Ltd (ABN 74 688 587 260), Queensland AU