For IT

For IT — how plant data is kept separate

A maintenance manager liked the demo. This is the page to send IT. Controls in the language of a security review — not an architecture dump, and not a certificate.

Controls IT already asks about

Built around common SaaS review language. This is how the product is designed — not a SOC 2, ISO 27001, or similar attestation posted on this page.

Logical tenant isolation
Each customer is a separate organization. Plant data is segregated so one company cannot read another.
RBAC and least privilege
Role-based access control. Admin, supervisor, technician, and trainee see only what their role allows. Training-only accounts are not a full console.
Unique identity
One person, one login. No shared plant password. Joiners come in by invite or join code from your team.
Encryption in transit (TLS)
Production traffic is HTTPS / TLS between the browser, the app, and the database and file stores.
Encryption at rest
Data and files sit on cloud infrastructure with provider-managed encryption at rest. We do not roll our own cipher on this page.
Private objects, time-bound access
Manuals, SOP video, and training photos are not a public folder. Access is authenticated and handed out as short-lived signed links.
Data minimization and retention
Passing training photos are deleted after the checkpoint passes. Failed or pending photos stay only for review. Raw SOP clips are cleaned up after the published job plan is in place.
Audit logging
Changes to people, roles, assets, and manuals are recorded for your organization so access can be reviewed.
SSO (SAML / OIDC)
Not on by default. When a customer IT team requires login through their identity provider, we stand up SAML or OIDC for that plant. Ask — we do not list providers here.
MFA (TOTP)
Optional authenticator-app second factor. Once enrolled, that login requires the six-digit code. Not SMS. We do not force it on every floor login on day one.
Subprocessors (AI)
Relevant excerpts are processed by contracted cloud AI providers to produce cited answers. Vendor / subprocessor list on request — not listed here.

Who this is for

fieldmAInt.ai holds OEM manuals, prints, job plans, and training records for a plant. This page is for InfoSec, IT, and the person filling out the vendor risk questionnaire.

Tenant isolation

Multi-tenant SaaS with logical tenant isolation. People authenticate into their organization only. Other companies cannot browse your manuals, chats, training records, or asset tree.

Identity and access

RBAC with least privilege. Accounts are individual — not a shared credential. Provisioning is invite or join code (joiner). Roles limit what they can do (admin, supervisor, technician, trainee). Training-only logins are need-to-know for the LMS, not a full CMMS console. Authenticator MFA (TOTP) is optional to enroll; once on, that account must complete it at login. Enterprise SSO (SAML / OIDC) is not a public toggle — we wire it when a customer identity provider requires it.

Encryption and transport

In production, the app is served over TLS (HTTPS). Sessions are authenticated. Files and records are stored with provider-managed encryption at rest. We do not publish cipher suites or key-management internals here.

Files and manuals

Private object storage with authenticated, time-bound access — not a public bucket listing. Passing training photos are deleted after the checkpoint (data minimization). Failed or pending photos stay only long enough for a supervisor to review. Raw SOP clips are cleaned up after the published job plan is in place.

How AI is used

Answers come from your manuals and prints, with citations. Relevant excerpts are processed by contracted cloud AI providers (subprocessors). We do not list vendors here. Ask, and we will send the current list. Plant manuals stay yours — we do not sell them or use them as advertising.

Audit trail and support access

An audit trail records changes to people, roles, assets, and manuals for your organization. Fieldmaint support can step into an org when you ask us to help (break-glass for support). That is not a second copy of your plant for other customers.

What we do not claim

No ad tracking or third-party advertising cookies. Marketing cookies are essential only — sign-in and this notice. This page is not a SOC 2 report, ISO 27001 certificate, HIPAA attestation, or penetration-test letter. Send the questionnaire if you need a control mapping.

Send the questionnaire

SIG, CAIQ, SOC 2-style, ISO-style, or your own vendor packet — plus the current AI subprocessor list. We complete that on request. We do not post certificates or vendor names on this page.