Security

Security your IT team can review line by line

Who can see what, how people sign in, where data is encrypted and how every change is recorded. Written for the security questionnaire you'll have to fill in.

Audit log

  1. ticket.auto_assigned#104218
    hash 9f2c·71e0prev 4ab0·3d77
  2. agent.arrived#104219
    hash c83e·05a9prev 9f2c·71e0
  3. jsa.submitted#104220
    hash 17d4·b2f6prev c83e·05a9
  4. ticket.resolved#104221
    hash e05b·9c13prev 17d4·b2f6

Chain verified · 02:00

Uptime targetMonitored continuously
99.9%
Maximum data loss (RPO)Backups audited
< 15 min
Audit log retentionVerified every night
7 yrs

Access

Each person sees their part of the operation

Access is granted by permission and by territory, so a dispatcher in Tijuana doesn't see Monterrey's tickets unless someone gives them that scope.

Permissions

One permission per action

Assigning a ticket, approving hours or exporting the audit log are separate permissions. Roles bundle them; five come ready and you can create your own.

Territories

Scoped by client and region

A person can read their own records, their territory's or the whole organization's. Territories follow each client's own hierarchy of regions and zones.

Grants

Temporary access with a reason

Special access is given to one person, for one permission, with a written reason and an expiry date, so it doesn't quietly become permanent.

Ceiling

Nobody grants more than they hold

An administrator can only give access they have themselves. Access moves sideways or down, never up.

Duties

Doing and checking are kept apart

The person who plans the roster doesn't approve the hours, and the technician who fixed a defect can't sign off the fix.

Clients and vendors

Outsiders see only their own records

A client sees its sites, tickets and equipment. A contractor sees the tickets assigned to it. Neither sees anyone else's.

Sign-in

Signing in, on the web and on the phone

Two-factor

Authenticator codes

Six-digit codes from an authenticator app, with single-use recovery codes. You choose which roles must use it.

Single sign-on

Your identity provider

Staff and vendors can sign in through your own provider over SAML 2.0 or OpenID Connect, with its groups mapped to waydot roles.

Sessions

Every device, visible and revocable

People see where they're signed in and can close any session. Changing a password signs out every other device.

Field app

Fingerprint or face on return

After five minutes in the background, the app asks for a fingerprint or face. Transfers and expenses ask again every time.

Throttling

Limits on repeated attempts

Five password attempts per minute, and five wrong codes end a two-factor challenge.

Deactivation

Leavers lose access at once

A deactivated account is refused on its next request, on every device, even with a valid token.

Data

Data protection

Encrypted in transit and at rest, with the most sensitive fields encrypted a second time inside the database.

In transit

TLS 1.3

Every connection between the console, the field app and the platform.

At rest

AES-256

Database volumes and file storage. Two-factor secrets, tax IDs, bank accounts and health data are also encrypted field by field.

Files

Short-lived signed links

Photos, receipts and employee documents are served through links that expire, and every link issued is logged.

Logs

Secrets masked before storage

Passwords, tokens, national IDs and bank accounts are replaced before anything reaches the audit log.

Location

Only during working time

The GPS trail is recorded on shift only and deleted after the retention period you set. Technicians never see each other's positions.

Privacy law

LFPDPPP requests

Data export and erasure requests under Mexico's LFPDPPP, and GDPR or CCPA where they apply. Erasure anonymizes the person and keeps the operational record.

Audit log

How the audit log records a change

Every workflow event, edit, sign-in and sensitive read goes through the same path.

  1. Written with the change

    The log entry is saved in the same database transaction as the change itself. One can't exist without the other.

    change + log entry: one transaction

    waydot console: Written with the changewaydot console: Written with the change
  2. Chained to the entry before

    Each entry's hash covers its content and the previous entry's hash. Altering, reordering or deleting a row breaks the chain.

    hash(n) = f(content(n), hash(n−1))

    waydot console: Chained to the entry beforewaydot console: Chained to the entry before
  3. Checked every night

    At 02:00 the whole chain is recalculated and the first row that no longer matches is reported.

    nightly verification · 02:00

    waydot console: Checked every nightwaydot console: Checked every night
  4. Kept for seven years

    One year stays searchable in the console; older entries move to compressed archives. The application can't delete log rows.

    1 year searchable · 7 years retained

    waydot console: Kept for seven yearswaydot console: Kept for seven years
  5. Read and exported with a trace

    Auditors filter by person, record, event or date. An export is itself logged before the data leaves.

    exports are logged too

    waydot console: Read and exported with a tracewaydot console: Read and exported with a trace

Devices

Phones in the field

Integrity

Rooted and emulated phones detected

The app checks for root, emulators, tampered builds and mock location. You decide whether a finding warns, limits the session or blocks sign-in.

Evidence

A private, encrypted vault

Photos, signatures and receipts are stored encrypted inside the app, out of reach of the phone's gallery and file manager.

Lost phones

Remote wipe

An administrator can wipe a lost device. On its next connection the app deletes its data and the session ends.

Commitments

The targets we measure against

Uptime
99.9%
Platform availability, monitored continuously
Maximum data loss
< 15 min
Recovery point objective, checked in backup audits
Field API response
< 300 ms
95th percentile, measured on the server
Console session timeout
120 min
Of inactivity, adjustable
Encryption at rest
AES-256
Databases and file storage
Audit retention
7 years
Archive included, verified nightly

Documents

Documents for your review

The contracts and policies procurement usually asks for, published and versioned.

See it on your own operation

A 30-minute briefing with your dispatch, payroll and asset flows on screen.

Book a briefing

Keep exploring

The visibility gap

What the office can't see

What running on WhatsApp and spreadsheets really costs, and what changes with one record.

Contact sales

See waydot with your own tickets

In 30 minutes we go through how you dispatch, pay and track equipment today, and show where waydot saves the most first.

  • 01A review of your current field operation
  • 02A custom ROI estimate for your fleet
  • 03Quick wins across operations, people, and assets
  • 04Expected impact and clear next steps

We reply within one business day. No sales sequences, no mailing lists.

By sending this form you accept that we use your details to answer your request, as described in our privacy notice.