Last updated July 20, 2026
Enterprise-grade practices for map intelligence and field operations.
TLS in transit and encrypted storage for sensitive data.
Secure sign-in, session management, and MFA support.
Role-based access across teams and territories.
Operational and security event monitoring.
DotlyMaps treats security as a core product requirement, not an afterthought. We apply defense-in-depth across infrastructure, application, and operational layers, and we publish our compliance roadmap transparently.
We design for least privilege, secure defaults, and continuous improvement. Our goal is to earn the trust of procurement teams, IT administrators, and security reviewers through honest, verifiable practices.
The DotlyMaps application enforces authentication on protected routes, validates input, and separates customer data by account boundaries. Security patches are prioritized based on risk and deployed through controlled release processes.
Production services run on enterprise cloud infrastructure with network segmentation, hardened configurations, and automated patching where applicable. We do not disclose specific cloud providers in public documentation unless configured by your administrator.
Customer map data, CRM sync records, and field activity remain under customer ownership. We process data only to deliver the DotlyMaps service and as described in our privacy documentation.
We support strong password requirements and multi-factor authentication for qualifying accounts. Session tokens are protected and expire according to security policy.
All customer traffic uses TLS. Sensitive data at rest is encrypted using industry-standard mechanisms on our cloud infrastructure.
We collect application and infrastructure telemetry to detect availability issues and security-relevant events. Logs are retained per our Data Retention Policy.
Critical production data is backed up on a regular schedule with tested restore procedures. See our Backup Policy for details.
We maintain runbooks for detection, triage, containment, and customer notification. See our Incident Response page for reporting contacts.
Our security program evolves through internal reviews, customer feedback, vulnerability reports, and planned third-party assessments. We never display certification badges until officially certified and approved for public display.