Skip to main content

Introducing Field Orchestrator: The Intelligence Layer for Financial Audit.

Learn More

Introducing Field Orchestrator: The Intelligence Layer for Financial Audit.

Learn More

Trust & Security

We understand the trust customers place in our product and services. The security and confidentiality of customer information is fundamental to everything we do. We therefore publish our information security and compliance practices, and keep our customers updated on our security practices and roadmap.

Industry-grade security and compliance

  • ISO 42001 certification badge

    The first international standard for AI management systems. It proves we apply responsible controls over artificial intelligence, managing risks ethically and transparently.

    More details
  • SOC 2 Type 2 certification badge

    An independent audit that validates our security, availability, and confidentiality controls over time. Your data is handled to the highest protection standards.

    More details
  • AIUC-1 attestation badge

    A use-control attestation confirming that our processes meet specific security and data-handling requirements, verified through external assessment.

    More details

Security

Security is built into the DNA of our organization and the core of our products. We employ best-in-class controls to secure data including encryption in transit and at rest, multi-factor authentication for access to systems, and internal programs centered around data security.

  • Encryption in transit & at rest

    Data in transit is protected by SHA-2 certificates over SHA-256/AES-128 connections. Data is encrypted at rest with AES-256, block-level storage encryption on Amazon Web Services.

  • Secure data architecture

    Fieldguide utilizes a secure, highly available database architecture, including leader-follower databases, automatic failover, Write-Ahead Logging, and point-in-time and snapshot-based rollback capabilities.

  • Multi-factor authentication

    All Fieldguide accounts utilize multi-factor authentication and require strong passwords that meet OWASP and IRS standards.

Planning, start to finish

  • Preliminary Analytics

    Ingests the trial balance and runs preliminary analytics across every balance. Surfaces the trends, fluctuations, and outliers worth a closer look, so planning starts from a clear picture rather than a blank workpaper.

  • Risk Identification

    Identifies risks from the client's industry, history, and risk profile. Ties each one to the relevant audit area and assertion, so the engagement is built around the risks that matter most.

  • Materiality and Scoping

    Sets materiality and scopes the engagement against the risks it surfaces. Lands the right procedures on the right risks, so the team avoids over-auditing low areas and under-auditing high ones.

  • Planning Procedures

    Builds the audit program from your methodology and prior-year context. Delivers it drafted and fully traceable, ready for the team to review, adjust, and execute, so fieldwork can start sooner.

Reliability & Availability

Fieldguide works with large organizations performing mission critical audit and compliance work. Our platform is architected for high availability, ensuring it's there to support your organization when you need it.

  • Secure infrastructure

    Fieldguide's cloud infrastructure is hosted and managed on Amazon Web Services (AWS)'s secure data centers in the United States that have been certified under: ISO 27001, SOC 1, SOC 2, PCI Level 1, FISMA Moderate, and Sarbanes-Oxley (SOX).

  • Continuous monitoring

    Application monitoring and alerting runs 24/7 on Fieldguide's systems, ensuring errors and performance anomalies are identified and addressed.

  • Guaranteed availability

    Fieldguide offers a financially-backed SLA of 99.9% uptime, ensuring your organization can count on our products when you need them.

Internal Reliability & Availability Programs

  • Business continuity

    Fieldguide develops Business Continuity Playbooks to plan for adverse business events. It runs through each playbook on at least a quarterly basis as part of a simulated testing process.

  • Incident management

    Incidents go through four phases: Investigation & Diagnosis, Notification Strategy, Containment, and Eradication. All incidents result in the creation of a Root Cause Analysis (RCA) report.

  • Change management

    Significant changes to the platform are controlled via a Change Control document that covers all aspects of the change, as well as necessary internal and external communications.

  • Secure SDLC

    Fieldguide follows a Software Development Lifecycle (SDLC) that outlines activities across the following phases: Planning, Design, Development, Deployment, Vulnerability Management.

Privacy

Fieldguide is committed to protecting the privacy of your organization's data. Our data classification policies, ability to export data, and our transparent list of vendors are designed to provide you with peace of mind as your firm scales.

  • GDPR and CCPA

    Fieldguide offers a Data Processing Addendum and adheres to Standard Contractual Clauses as a means to transfer data from the EU to the US. More information on Fieldguide's data privacy with respect to GDPR and CCPA can be found in our Privacy Policy.

  • Data ownership & portability

    Your organization owns its data. Fieldguide makes it easy to export data in standard formats. Data deletion requests can be directed to privacy@fieldguide.io.

  • Data transparency

    Fieldguide does not sell or share your data with 3rd parties. A limited number of data subprocessors are used to support certain Fieldguide operations and services, based on principles of least-necessary access.