Security and data residency

Where survey data is kept, who inside an organisation may open it, and what this pilot does not yet do. We hold no third-party security certification and claim none.

Where the data is

  • This deployment runs in Amazon Web Services’ Mumbai region. The region is pinned in the infrastructure definition and checked before any change can be applied, and a second check refuses a deployment whose declared country and actual region disagree.
  • Databases, uploaded files and published releases are encrypted at rest with a key belonging to this deployment. The database is not reachable from the internet and requires an encrypted connection.
  • Everything is served over TLS 1.2 or later, preferring 1.3. Port 80 exists only to redirect to HTTPS, and nothing is served on it.

The disclosed exceptions

Two operational exceptions to that residency are disclosed in the privacy policy, both of them about email, and neither carries survey data or spatial coordinates: outbound transactional email is dispatched through Cloudflare’s email service, and correspondence to our published mailboxes is received through Google Workspace. The policy’s sub-processor table is the full list of third parties and says where each one holds what.

The privacy policy

Who may open what

Access is scoped at three levels — the organisation, a branch and a project — with five roles at organisation level and three at each of the others. A request is authorised against the act it is trying to perform rather than against a role name.

Role hierarchy is itself a plan capability, and this is worth knowing before you rely on it: where a plan does not include it the organisation runs flat and every member resolves as at least an administrator. The plans page states what each plan includes.

Pricing

One organisation’s files reach another only by an explicit act on both sides — a delivery, or a project share where the sender allows the download. Nothing is shared by address alone, and there is no cross-organisation write.

Second factor

Any account can enrol an authenticator app: six-digit codes on a thirty-second period, ten single-use recovery codes issued at enrolment, and a lock-out after repeated wrong codes. It is available to every customer account and strongly recommended for administrators; it is not currently mandatory for customers.

For Alonstech staff it is not optional. An operator without an enrolled second factor is refused the staff console outright.

What this pilot does not do

There is no antivirus scanner. ZIP archives and PDF documents are checked for structure and integrity and are not scanned for malware, and a PDF today receives format identification only. This is published in the terms of service and shown to the person uploading, and it is the notice they are given:

During the pilot, ZIP archives and PDF documents are checked for structure and integrity but are not scanned for malware. They can be downloaded by members of your organisation, and by another organisation if you share a release with them and allow the download. Please do not upload a file you received from someone else and have not checked yourself.

What does happen: a ZIP is opened and metered for entry count, expansion and path traversal before it is accepted, and LAS, GeoJSON and DXF each have a structural validator of their own.

Certifications

We hold none, and we do not describe ourselves as compliant with a standard nobody has assessed us against. What is written above is what the deployment does, and each statement can be checked against the terms of service and the privacy policy.

The terms of service

Ready to look at the product?

The plans page lists what each plan includes and what it costs. If you would rather ask a person first, the support page is the way to reach one.